CVE-2024-30302: ZDI-CAN-23077: Adobe Acrobat Reader DC AcroForm Use-After-Free Information Disclosure Vulnerability
Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30302?
CVE-2024-30302 is classified as a critical vulnerability due to its potential for sensitive memory disclosure.
How do I fix CVE-2024-30302?
To address CVE-2024-30302, users should update Adobe Acrobat Reader and Acrobat DC to the latest versions provided by Adobe.
What versions of Adobe Acrobat are affected by CVE-2024-30302?
Adobe Acrobat Reader versions up to 20.005.30539 and Acrobat DC versions up to 23.008.20470 are impacted by CVE-2024-30302.
What type of vulnerability is CVE-2024-30302?
CVE-2024-30302 is a Use After Free vulnerability that can lead to sensitive information exposure.
Can CVE-2024-30302 be exploited remotely?
Exploitation of CVE-2024-30302 requires user interaction, meaning an attacker must trick the user into opening a malicious PDF file.