CVE-2024-20752: ZDI-CAN-22653: Adobe Bridge PS File Parsing Use-After-Free Remote Code Execution Vulnerability
Bridge versions 13.0.5, 14.0.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20752?
CVE-2024-20752 has a high severity rating due to its potential for arbitrary code execution.
How do I fix CVE-2024-20752?
To mitigate CVE-2024-20752, update Adobe Bridge to version 13.0.6 or later, or version 14.0.2 or later.
What types of systems are affected by CVE-2024-20752?
CVE-2024-20752 affects Adobe Bridge versions 13.0.5 and 14.0.1 and earlier, across supported operating systems.
What conditions are required for exploitation of CVE-2024-20752?
Exploitation of CVE-2024-20752 requires the victim to open a specially crafted malicious file.
Is user interaction needed for CVE-2024-20752 exploitation?
Yes, user interaction is necessary as the attack is triggered when the victim opens a malicious file.