CVE-2024-45112: Acrobat Reader | Access of Resource Using Incompatible Type ('Type Confusion') (CWE-843)
Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Type Confusion vulnerability that could result in arbitrary code execution in the context of the current user. This issue occurs when a resource is accessed using a type that is not compatible with the actual object type, leading to a logic error that an attacker could exploit. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45112?
CVE-2024-45112 is classified as a critical severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2024-45112?
To fix CVE-2024-45112, users should update Adobe Acrobat Reader to version 24.002.21006 or later.
Which versions of Acrobat Reader are affected by CVE-2024-45112?
CVE-2024-45112 affects Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier.
Can CVE-2024-45112 be exploited remotely?
Yes, CVE-2024-45112 can potentially be exploited remotely if a user opens a malicious PDF file.
What type of vulnerability is CVE-2024-45112?
CVE-2024-45112 is a Type Confusion vulnerability that could lead to arbitrary code execution.