First published: Wed Aug 14 2024(Updated: )
Acrobat Reader versions 20.005.30636, 24.002.21005, 24.001.30159, 20.005.30655, 24.002.20965, 24.002.20964, 24.001.30123, 24.003.20054 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary code execution. This vulnerability arises when the timing of actions changes the state of a resource between the checking of a condition and the use of the resource, allowing an attacker to manipulate the resource in a harmful way. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Adobe Acrobat Reader | >=20.001.30005<20.005.30655 | |
Adobe Acrobat Reader | >=24.001.20604<24.001.30159 | |
Adobe Acrobat | >=15.008.20082<24.002.21005 | |
Adobe Acrobat Reader | >=20.001.3005<20.005.30655 | |
Adobe Acrobat Reader | >=15.008.20082<24.002.21005 | |
Any of | ||
Apple iOS and macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-39420 is a critical vulnerability due to its potential for arbitrary code execution.
To mitigate CVE-2024-39420, users should update Adobe Acrobat Reader and Acrobat DC to the latest versions.
Adobe Acrobat Reader versions 20.005.30636 and earlier, as well as multiple other specific versions, are affected by CVE-2024-39420.
CVE-2024-39420 is classified as a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability.
Yes, CVE-2024-39420 could potentially lead to data loss or system compromise due to arbitrary code execution.