Adobe completes fix for Reader bug with known PoC exploit (CVE-2024-41869)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-39383 | Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Use After Free vulnerability that could result in a Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. NVD description · AI analysis pending | 7.8 | 3% |
| — | ||
| CVE-2024-41869 +1 in the same advisory: …45112 | Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After Free vulnerability that could result in a Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. NVD description · AI analysis pending | 7.8 | 2% |
| — |
Full article281 words · extracted from helpnetsecurity.com · click to collapse
Among the security updates released by Adobe on Tuesday are those for various versions of Adobe Acrobat and Reader, which fix two critical flaws that could lead to arbitrary code execution: CVE-2024-45112 and CVE-2024-41869.

Nothing in the advisory points to a need for users to implement the updates quickly, but the fix for CVE-2024-41869 is actually an additional, more complete fix for CVE-2024-39383, which was supposedly addressed with a security update released in August 2024.
The kicker is that a PoC exploit for CVE-2024-39383 has been detected by EXPMON, a publicly available sandbox-based system for detecting advanced file-based exploits, after a huge public PDF sample set has been tested with it and it detected a crash and reported it as a potential zero-day attack after analyzing a specific file.
What to do?
Both CVE-2024-39383 and CVE-2024-41869 have been reported to Adobe by Haifei Li, who works at Check Point Research and is one of the creators of EXPMON.
The PoC exploit in question is not a full working exploit and the file did not carry a malicious payload, raising the (still unanswered) question of whether it’s an unfinished 0-day exploit leaked by mistake or whether the PDF file was simply crafted for “good-purpose PDF app testing”.
So, in essence, it’s unknown whether the exploit is being used in the wild (after having been duly polished).
But, since EXPMON developers plan to share the PDF sample in question and a blog post about the exploit soon, “users are highly encouraged to apply the new update as soon as possible.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/09/12/cve-2024-41869/