First published: Wed May 15 2024(Updated: )
Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Adobe Acrobat | >=15.007.20033<24.002.20759 | |
Adobe Acrobat Reader | >=15.007.20033<24.002.20759 | |
Any of | ||
Apple macOS | ||
Microsoft Windows | ||
All of | ||
Any of | ||
Adobe Acrobat Reader | >=20.001.30002<20.005.30635 | |
Adobe Acrobat Reader | >=20.001.30002<20.005.30635 | |
Apple macOS | ||
All of | ||
Any of | ||
Adobe Acrobat Reader | >=20.001.30002<20.005.30636 | |
Adobe Acrobat Reader | >=20.001.30002<20.005.30636 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34098 has a high severity level as it allows for arbitrary code execution through improper input validation.
To fix CVE-2024-34098, update Adobe Acrobat and Acrobat Reader to the latest version that is not affected by this vulnerability.
Adobe Acrobat versions 20.005.30574, 24.002.20736 and earlier are affected by CVE-2024-34098.
If exploited, CVE-2024-34098 could result in arbitrary code execution in the context of the current user.
Yes, exploitation of CVE-2024-34098 requires user interaction, such as opening a malicious document.