Description

Acrobat Reader versions 20.005.30636, 24.002.21005, 24.001.30159, 20.005.30655, 24.002.20965, 24.002.20964, 24.001.30123, 24.003.20054 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary code execution. This vulnerability arises when the timing of actions changes the state of a resource between the checking of a condition and the use of the resource, allowing an attacker to manipulate the resource in a harmful way. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

INFO

Published Date :

2024-08-14T15:07:28.784Z

Last Modified :

2024-09-16T12:30:11.437Z

Source :

adobe
AFFECTED PRODUCTS

The following products are affected by CVE-2024-39420 vulnerability.

Vendors Products
Adobe
  • Acrobat
  • Acrobat Dc
  • Acrobat Reader
  • Acrobat Reader Dc
Apple
  • Macos
Microsoft
  • Windows
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-39420.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact