« Back to list

CVE-2024-41832

Status: ModifiedMedium (5.5)—

Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (4)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2024-41832",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-41832",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-14T15:51:39.327561Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@adobe.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@adobe.com",
      "affectedData": [
        {
          "vendor": "Adobe",
          "product": "Acrobat Reader",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "24.001.30123"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:*:windows:*:*"
          ],
          "vendor": "adobe",
          "product": "acrobat_dc",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "24.002.20991"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:*:macos:*:*"
          ],
          "vendor": "adobe",
          "product": "acrobat_dc",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "24.002.20964"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*"
          ],
          "vendor": "adobe",
          "product": "acrobat",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "24.001.30123"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:adobe:acrobat:*:*:*:*:*:windows:*:*"
          ],
          "vendor": "adobe",
          "product": "acrobat",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "24.001.30123"
            },
            {
              "status": "affected",
              "version": "20.0",
              "versionType": "semver",
              "lessThanOrEqual": "20.005.30636"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:adobe:acrobat:*:*:*:*:*:macos:*:*"
          ],
          "vendor": "adobe",
          "product": "acrobat",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "24.001.30123"
            },
            {
              "status": "affected",
              "version": "20.0",
              "versionType": "semver",
              "lessThanOrEqual": "20.005.30635"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:windows:*:*"
          ],
          "vendor": "adobe",
          "product": "acrobat_reader",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "20.005.30636"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:macos:*:*"
          ],
          "vendor": "adobe",
          "product": "acrobat_reader",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "20.005.30635"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:macos:*:*"
          ],
          "vendor": "adobe",
          "product": "acrobat_reader_dc",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "24.002.20964"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:windows:*:*"
          ],
          "vendor": "adobe",
          "product": "acrobat_reader_dc",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "24.002.20991"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-08-14T15:15:28.530",
  "references": [
    {
      "url": "https://helpx.adobe.com/security/products/acrobat/apsb24-57.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2002",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@adobe.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file."
    },
    {
      "lang": "es",
      "value": " Las versiones de Acrobat Reader 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 y anteriores se ven afectadas por una vulnerabilidad de lectura fuera de los límites que podría provocar la divulgación de memoria confidencial. Un atacante podría aprovechar esta vulnerabilidad para evitar mitigaciones como ASLR. La explotación de este problema requiere la interacción del usuario, ya que la víctima debe abrir un archivo malicioso."
    }
  ],
  "lastModified": "2026-06-17T07:48:18.663",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9311FEC-D9CC-421C-8E5E-8131E460FC42",
              "versionEndExcluding": "20.005.30655",
              "versionStartIncluding": "20.001.30005"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A09E4B8-DB3B-45EC-B441-2C9549D299B1",
              "versionEndExcluding": "24.001.30159",
              "versionStartIncluding": "24.001.20604"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D555A6CB-9EDF-4CA2-B8E5-04A9D212FD8B",
              "versionEndExcluding": "24.002.21005",
              "versionStartIncluding": "15.008.20082"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "883444C8-35EB-4BDF-A14C-C4C5BF97239A",
              "versionEndExcluding": "20.005.30655",
              "versionStartIncluding": "20.001.3005"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9CE03784-4780-4313-A27A-37B265BF3F9D",
              "versionEndExcluding": "24.002.21005",
              "versionStartIncluding": "15.008.20082"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@adobe.com"
}