CVE-2024-20728: ZDI-CAN-22727: Adobe Acrobat Pro DC Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability
Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Acrobat Readerto a version that resolves this vulnerability.Fixed in 23.008.20470Patch ZDI-CAN-22727 - Upgrade
Upgrade
Adobe Acrobat Pro DCto a version that resolves this vulnerability.Fixed in 20.005.30539Patch ZDI-CAN-22727
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20728?
CVE-2024-20728 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2024-20728?
To address CVE-2024-20728, update Adobe Acrobat and Adobe Acrobat Reader to the latest version available.
What versions are affected by CVE-2024-20728?
CVE-2024-20728 affects Adobe Acrobat Reader versions 20.005.30539 and 23.008.20470 and earlier versions.
Can CVE-2024-20728 be exploited remotely?
Exploitation of CVE-2024-20728 requires user interaction, as it necessitates the victim to open a malicious PDF file.
What are the potential impacts of CVE-2024-20728?
The impact of CVE-2024-20728 includes the possibility of arbitrary code execution in the context of the current user.