logo

Adobe fixed Acrobat bug, neglected to mention whole zero-day exploit thing

ID: 314d1339-b4fb-5e01-a23e-1bbfee7f1b6e

STIX ID: report--314d1339-b4fb-5e01-a23e-1bbfee7f1b6e

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-09-12

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Adobe fixed a use-after-free RCE in Acrobat (CVE-2024-41869) during Patch Tuesday; researcher Expmon reported the bug in June and says a proof-of-concept PDF exists. Adobe's initial patch was incomplete, the vendor assigned a "critical" severity despite a 7.8 CVSS score, and Expmon plans to release the PoC sample — increasing the likelihood of exploitation once the sample is public.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.