CVE-2024-20729: TALOS-2023-1890 - Adobe Acrobat Reader Annot3D object zoom event use-after-free vulnerability
Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Because exploitation requires user interaction (victim must open a malicious file), reduce exposure by restricting/controlling delivery and opening of untrusted files in the Acrobat Reader environment.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20729?
CVE-2024-20729 is categorized as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2024-20729?
To fix CVE-2024-20729, update Adobe Acrobat Reader to the latest version that addresses this vulnerability.
What versions of Adobe Acrobat are affected by CVE-2024-20729?
CVE-2024-20729 affects Adobe Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier.
What is the nature of the vulnerability in CVE-2024-20729?
CVE-2024-20729 is a Use After Free vulnerability that could allow an attacker to execute arbitrary code.
Does exploitation of CVE-2024-20729 require user interaction?
Yes, exploitation of CVE-2024-20729 requires user interaction, as a victim must open a malicious file.