cbcvebase.
CVE-2024-39420
published 2024-08-14

CVE-2024-39420: Acrobat Reader versions 20.005.30636, 24.002.21005, 24.001.30159, 20.005.30655, 24.002.20965, 24.002.20964, 24.001.30123, 24.003.20054 and earlier are affected…

PriorityP337high7CVSS 3.1
AVLACHPRNUIRSUCHIHAH
EPSS
3.49%
87.9th percentile
Acrobat Reader versions 20.005.30636, 24.002.21005, 24.001.30159, 20.005.30655, 24.002.20965, 24.002.20964, 24.001.30123, 24.003.20054 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary code execution. This vulnerability arises when the timing of actions changes the state of a resource between the checking of a condition and the use of the resource, allowing an attacker to manipulate the resource in a harmful way. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Affected

6 ranges
VendorProductVersion rangeFixed in
adobeacrobat>= 20.001.30005 < 20.005.3065520.005.30655
adobeacrobat>= 24.001.20604 < 24.001.3015924.001.30159
adobeacrobat_dc>= 15.008.20082 < 24.002.2100524.002.21005
adobeacrobat_reader<= 24.003.20054
adobeacrobat_reader>= 20.001.3005 < 20.005.3065520.005.30655
adobeacrobat_reader_dc>= 15.008.20082 < 24.002.2100524.002.21005
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.