CVE-2024-45112 is a Type Confusion vulnerability affecting Adobe Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054, and earlier, impacting users on Adobe, Apple, and Microsoft platforms. This flaw, rated High severity (CVSS 7.8), allows for arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it's not listed in CISA's KEV catalog, there has been limited community discussion and media coverage, indicating some awareness of the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.005.30680CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:* | ||
>= 24.001.0, < 24.001.30187CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:* | ||
>= 24.003.0, < 24.003.20112CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
< 20.005.30680CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:* | ||
>= 24.003.0, < 24.003.20112CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.