First published: Thu Aug 22 2024(Updated: )
Acrobat Reader versions 127.0.2651.105 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Edge | ||
Microsoft Edge Beta | <128.0.2739.42 | |
Adobe Acrobat Reader Notification Manager | ||
Microsoft Edge Beta | <128.0.2739.42 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-41879 has a high severity rating due to its potential to allow arbitrary code execution.
To fix CVE-2024-41879, update Adobe Acrobat Reader to the latest version or ensure that Microsoft Edge is running the latest build.
CVE-2024-41879 affects Adobe Acrobat Reader versions earlier than 127.0.2651.105 and Microsoft Edge versions up to 128.0.2739.42.
Users of Adobe Acrobat Reader and Microsoft Edge who open malicious files are at risk due to CVE-2024-41879.
Yes, exploitation of CVE-2024-41879 requires user interaction as the victim must open a malicious file.