CVE-2024-41879: New Edge T5 MSRC Case [DCMSFT-1294]
Acrobat Reader versions 127.0.2651.105 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Other sources
Adobe Systems Incorporated: CVE-2024-41879 Adobe PDF Viewer Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41879?
CVE-2024-41879 has a high severity rating due to its potential to allow arbitrary code execution.
How do I fix CVE-2024-41879?
To fix CVE-2024-41879, update Adobe Acrobat Reader to the latest version or ensure that Microsoft Edge is running the latest build.
What are the affected versions for CVE-2024-41879?
CVE-2024-41879 affects Adobe Acrobat Reader versions earlier than 127.0.2651.105 and Microsoft Edge versions up to 128.0.2739.42.
Who is at risk with CVE-2024-41879?
Users of Adobe Acrobat Reader and Microsoft Edge who open malicious files are at risk due to CVE-2024-41879.
Does CVE-2024-41879 require user interaction to exploit?
Yes, exploitation of CVE-2024-41879 requires user interaction as the victim must open a malicious file.