CVE-2024-39425: Security vulnerability in AdobeARMHelper
Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to privilege escalation. Exploitation of this issue require local low-privilege access to the affected system and attack complexity is high.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39425?
CVE-2024-39425 has a high-severity rating due to its potential for privilege escalation.
How do I fix CVE-2024-39425?
To fix CVE-2024-39425, update Adobe Acrobat Reader to version 20.005.30655 or later, or 24.001.30159 or later.
Which versions of Adobe Acrobat are affected by CVE-2024-39425?
CVE-2024-39425 affects Adobe Acrobat Reader versions up to 20.005.30636 and 24.002.20965, among others.
Can CVE-2024-39425 be exploited remotely?
No, exploitation of CVE-2024-39425 requires local low-privilege access to the system.
What is a Time-of-check Time-of-use (TOCTOU) vulnerability like CVE-2024-39425?
A Time-of-check Time-of-use vulnerability, such as CVE-2024-39425, occurs when a system checks a condition before performing an action, allowing an attacker to exploit the window of opportunity between the two events.