QID 379367

Date Published: 2024-02-14

QID 379367: Adobe Acrobat and Reader Arbitrary Code Execution Vulnerability (APSB24-07)

Adobe Acrobat and Reader are applications for handling PDF files developed and marketed by Adobe Systems.

Affected Versions:
Adobe Acrobat DC - Continuous - 23.008.20470 and prior Windows and MacOS
Adobe Acrobat Reader DC - Continuous - 23.008.20470 and prior Windows and MacOS
Adobe Acrobat 2020 - Classic 2020 - 20.005.30539 and prior Windows and MacOS
Adobe Acrobat Reader 2020 - Classic 2020 - 20.005.30539 and prior Windows and MacOS

QID Detection Logic:(Authenticated)
This QID checks vulnerable versions of Adobe Acrobat and Reader.

Successful exploitation could lead to arbitrary code execution, application denial-of-service, and memory leak.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution

    Adobe has released fix to address this issue. Customers are advised to refer to APSB24-07 for updates pertaining to this vulnerability.

    Software Advisories
    Advisory ID Software Component Link
    APSB24-07 URL Logo helpx.adobe.com//security/products/acrobat/apsb24-07.html