First published: Thu Jul 25 2024(Updated: )
Acrobat for Edge versions 126.0.2592.81 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Edge | ||
Microsoft Edge Beta | <127.0.2651.74 | |
Adobe Acrobat | <=126.0.2592.81 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-39379 is classified as a high-risk vulnerability due to its potential to disclose sensitive memory.
To mitigate CVE-2024-39379, users should upgrade to the latest version of Adobe Acrobat for Edge or Microsoft Edge.
CVE-2024-39379 impacts Adobe Acrobat for Edge versions up to 126.0.2592.81 and Microsoft Edge versions up to 127.0.2651.74.
Yes, exploitation of CVE-2024-39379 could potentially lead to data breaches by allowing unauthorized access to sensitive memory.
Yes, exploitation of CVE-2024-39379 requires user interaction to trigger the vulnerability.