First published: Tue Dec 10 2024(Updated: )
PDFL SDK versions 21.0.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Adobe PDF Library SDK | <21.0.0.7 | |
Any of | ||
Apple macOS | ||
Linux Kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49513 is classified as a high severity vulnerability due to its potential for arbitrary code execution.
To fix CVE-2024-49513, upgrade to Adobe PDF Library SDK version 21.0.0.7 or later.
CVE-2024-49513 can lead to arbitrary code execution if the vulnerable SDK processes a maliciously crafted PDF file.
CVE-2024-49513 affects Adobe PDF Library SDK versions 21.0.0.5 and earlier.
Yes, exploitation of CVE-2024-49513 requires user interaction, specifically opening a malicious PDF file.