cbcvebase.
CVE-2024-41869
published 2024-09-13

CVE-2024-41869: Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After Free vulnerability that could result in…

PriorityP278high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
2.31%
81.5th percentile
Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Affected

6 ranges
VendorProductVersion rangeFixed in
adobeacrobat< 20.005.3068020.005.30680
adobeacrobat>= 24.001.0 < 24.001.3018724.001.30187
adobeacrobat_dc>= 24.003.0 < 24.003.2011224.003.20112
adobeacrobat_reader< 20.005.3068020.005.30680
adobeacrobat_reader<= 24.003.20054
adobeacrobat_reader_dc>= 24.003.0 < 24.003.2011224.003.20112

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered by opening a specially crafted PDF document; detection should focus on PDF files that cause a use-after-free crash in Adobe Acrobat/Reader processes.
  • A public proof-of-concept exploit exists in the wild (submitted to EXPMON from a public source); samples were PDF files that caused a crash in Acrobat Reader, confirming exploitability without a malicious payload drop.
  • The incomplete August patch (APSB24-57) did not fully remediate the UAF; even on the 'patched' version the app crashed after closing additional dialogs — monitor for Acrobat Reader crashes on versions prior to the September 2024 APSB24-70 fix.
  • Adobe confirmed a known PoC that causes Acrobat/Reader to crash exists in the wild; monitor for abnormal termination/crash telemetry of AcroRd32.exe or Acrobat.exe processes when opening PDF files.
  • ·Exploitation requires user interaction — the victim must open a malicious PDF file; drive-by or unauthenticated remote exploitation without user action is not possible.
  • ·The August 2024 patch (APSB24-57) did NOT fully fix the vulnerability; only the September 2024 update (APSB24-70) is confirmed to remediate CVE-2024-41869. Ensure patching targets the correct bulletin.
  • ·The public PoC is a work in progress and contains no malicious payload; however, the UAF primitive is confirmed and could be weaponized for RCE.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.