Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m44h-648c-4ggp

Опубликовано: 13 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Type Confusion vulnerability that could result in arbitrary code execution in the context of the current user. This issue occurs when a resource is accessed using a type that is not compatible with the actual object type, leading to a logic error that an attacker could exploit. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Type Confusion vulnerability that could result in arbitrary code execution in the context of the current user. This issue occurs when a resource is accessed using a type that is not compatible with the actual object type, leading to a logic error that an attacker could exploit. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS

Процентиль: 62%
0.00436
Низкий

7.8 High

CVSS3

Дефекты

CWE-843

Связанные уязвимости

CVSS3: 7.8
nvd
больше 1 года назад

Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Type Confusion vulnerability that could result in arbitrary code execution in the context of the current user. This issue occurs when a resource is accessed using a type that is not compatible with the actual object type, leading to a logic error that an attacker could exploit. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 8.6
fstec
больше 1 года назад

Уязвимость программ просмотра и редактирования PDF-файлов Adobe Acrobat Document Cloud, Adobe Acrobat Reader Document Cloud, Adobe Acrobat 2020, Adobe Acrobat Reader 2020, Adobe Acrobat 2024, связанная с ошибками смешения типов данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 62%
0.00436
Низкий

7.8 High

CVSS3

Дефекты

CWE-843