CVE-2024-41869
published 2024-09-13CVE-2024-41869: Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After Free vulnerability that could result in…
PriorityP278high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
2.31%
81.5th percentile
Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | < 20.005.30680 | 20.005.30680 |
| adobe | acrobat | >= 24.001.0 < 24.001.30187 | 24.001.30187 |
| adobe | acrobat_dc | >= 24.003.0 < 24.003.20112 | 24.003.20112 |
| adobe | acrobat_reader | < 20.005.30680 | 20.005.30680 |
| adobe | acrobat_reader | <= 24.003.20054 | — |
| adobe | acrobat_reader_dc | >= 24.003.0 < 24.003.20112 | 24.003.20112 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered by opening a specially crafted PDF document; detection should focus on PDF files that cause a use-after-free crash in Adobe Acrobat/Reader processes. ↗
- →A public proof-of-concept exploit exists in the wild (submitted to EXPMON from a public source); samples were PDF files that caused a crash in Acrobat Reader, confirming exploitability without a malicious payload drop. ↗
- →The incomplete August patch (APSB24-57) did not fully remediate the UAF; even on the 'patched' version the app crashed after closing additional dialogs — monitor for Acrobat Reader crashes on versions prior to the September 2024 APSB24-70 fix. ↗
- →Adobe confirmed a known PoC that causes Acrobat/Reader to crash exists in the wild; monitor for abnormal termination/crash telemetry of AcroRd32.exe or Acrobat.exe processes when opening PDF files. ↗
- ·Exploitation requires user interaction — the victim must open a malicious PDF file; drive-by or unauthenticated remote exploitation without user action is not possible. ↗
- ·The August 2024 patch (APSB24-57) did NOT fully fix the vulnerability; only the September 2024 update (APSB24-70) is confirmed to remediate CVE-2024-41869. Ensure patching targets the correct bulletin. ↗
- ·The public PoC is a work in progress and contains no malicious payload; however, the UAF primitive is confirmed and could be weaponized for RCE. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cwq2-m7r2-f7pg: Acrobat Reader versions 24
ghsa_unreviewed·2024-09-13
CVE-2024-41869 [HIGH] CWE-416 GHSA-cwq2-m7r2-f7pg: Acrobat Reader versions 24
Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
VulnCheck
Adobe Acrobat and Reader Use After Free Remote Code Execution Vulnerability
vulncheck·2024·CVSS 7.8
CVE-2024-41869 [HIGH] Adobe Acrobat and Reader Use After Free Remote Code Execution Vulnerability
Adobe Acrobat and Reader Use After Free Remote Code Execution Vulnerability
A use after free vulnerability exists in Adobe Acrobat and Reader that could allow for arbitrary code execution.
Affected: Adobe Acrobat and Reader
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.cybersecurity-help.cz/vdb/SB20240910117
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Adobe fixes Acrobat Reader zero-day with public PoC exploit
blogs_bleepingcomputer·2024-09-11·CVSS 7.8
CVE-2024-41869 [HIGH] Adobe fixes Acrobat Reader zero-day with public PoC exploit
## Adobe fixes Acrobat Reader zero-day with public PoC exploit
## Lawrence Abrams
A cybersecurity researcher is urging users to upgrade Adobe Acrobat Reader after a fix was released yesterday for a remote code execution zero-day with a public in-the-wild proof-of-concept exploit.
The flaw is tracked as CVE-2024-41869 and is a critical use after free vulnerability that could lead to remote code execution when opening a specially crafted PDF document.
A "use after free" bug is when a program tries to access data in a memory location that has already been freed or released. This causes unexpected behavior, such as a program crashing or freezing.
However, if a threat actor is able to store malicious code in that memory location, and the program subsequently accesses it, it could be used t
Zscaler
Zscaler found Adobe security vulnerabilities | 09-10-2024
blogs_zscaler
Zscaler found Adobe security vulnerabilities | 09-10-2024
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
2024-09-13
Published
Exploited in the wild