« Volver al listado

CVE-2024-39425

Estado: AnalizadaAlta (7)—

Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to privilege escalation. Exploitation of this issue require local low-privilege access to the affected system and attack complexity is high.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-39425",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-39425",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-14T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@adobe.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@adobe.com",
      "affectedData": [
        {
          "vendor": "Adobe",
          "product": "Acrobat Reader",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "24.001.30123"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:*:windows:*:*"
          ],
          "vendor": "adobe",
          "product": "acrobat_dc",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "24.002.20991"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:*:macos:*:*"
          ],
          "vendor": "adobe",
          "product": "acrobat_dc",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "24.002.20964"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*"
          ],
          "vendor": "adobe",
          "product": "acrobat",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "24.001.30123"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:adobe:acrobat:*:*:*:*:*:windows:*:*"
          ],
          "vendor": "adobe",
          "product": "acrobat",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "24.001.30123"
            },
            {
              "status": "affected",
              "version": "20.0",
              "versionType": "semver",
              "lessThanOrEqual": "20.005.30636"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:adobe:acrobat:*:*:*:*:*:macos:*:*"
          ],
          "vendor": "adobe",
          "product": "acrobat",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "24.001.30123"
            },
            {
              "status": "affected",
              "version": "20.0",
              "versionType": "semver",
              "lessThanOrEqual": "20.005.30635"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:windows:*:*"
          ],
          "vendor": "adobe",
          "product": "acrobat_reader",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "20.005.30636"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:macos:*:*"
          ],
          "vendor": "adobe",
          "product": "acrobat_reader",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "20.005.30635"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:macos:*:*"
          ],
          "vendor": "adobe",
          "product": "acrobat_reader_dc",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "24.002.20964"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:windows:*:*"
          ],
          "vendor": "adobe",
          "product": "acrobat_reader_dc",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "24.002.20991"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-08-14T15:15:25.883",
  "references": [
    {
      "url": "https://helpx.adobe.com/security/products/acrobat/apsb24-57.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@adobe.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@adobe.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-367"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to privilege escalation. Exploitation of this issue require local low-privilege access to the affected system and attack complexity is high."
    },
    {
      "lang": "es",
      "value": " Las versiones de Acrobat Reader 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 y anteriores se ven afectadas por una vulnerabilidad de condición de ejecución de Time-of-check Time-of-use (TOCTOU) que podría provocar una escalada de privilegios. La explotación de este problema requiere acceso local con pocos privilegios al sistema afectado y la complejidad del ataque es alta."
    }
  ],
  "lastModified": "2026-06-17T07:41:54.993",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9311FEC-D9CC-421C-8E5E-8131E460FC42",
              "versionEndExcluding": "20.005.30655",
              "versionStartIncluding": "20.001.30005"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A09E4B8-DB3B-45EC-B441-2C9549D299B1",
              "versionEndExcluding": "24.001.30159",
              "versionStartIncluding": "24.001.20604"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D555A6CB-9EDF-4CA2-B8E5-04A9D212FD8B",
              "versionEndExcluding": "24.002.21005",
              "versionStartIncluding": "15.008.20082"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "883444C8-35EB-4BDF-A14C-C4C5BF97239A",
              "versionEndExcluding": "20.005.30655",
              "versionStartIncluding": "20.001.3005"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9CE03784-4780-4313-A27A-37B265BF3F9D",
              "versionEndExcluding": "24.002.21005",
              "versionStartIncluding": "15.008.20082"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@adobe.com"
}