CVE-2024-30303: ZDI-CAN-23044: Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution Vulnerability
Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30303?
CVE-2024-30303 has a high severity rating due to its potential for arbitrary code execution.
How do I fix CVE-2024-30303?
To fix CVE-2024-30303, update Adobe Acrobat Reader or Acrobat DC to the latest version as recommended by Adobe.
What versions are affected by CVE-2024-30303?
Versions 20.005.30539, 23.008.20470 and earlier of Adobe Acrobat Reader and Acrobat DC are affected by CVE-2024-30303.
Can CVE-2024-30303 be exploited remotely?
CVE-2024-30303 requires user interaction to exploit, as it necessitates opening a malicious document.
What is a Use After Free vulnerability in CVE-2024-30303?
A Use After Free vulnerability in CVE-2024-30303 allows attackers to execute arbitrary code by manipulating memory after it has been freed.