Adobe fixed Acrobat bug, neglected to mention whole zero-day exploit thing
ID: 314d1339-b4fb-5e01-a23e-1bbfee7f1b6e
STIX ID: report--314d1339-b4fb-5e01-a23e-1bbfee7f1b6e
Feed Name: The Register (Security)
Threat Score
Adobe fixed a use-after-free RCE in Acrobat (CVE-2024-41869) during Patch Tuesday; researcher Expmon reported the bug in June and says a proof-of-concept PDF exists. Adobe's initial patch was incomplete, the vendor assigned a "critical" severity despite a 7.8 CVSS score, and Expmon plans to release the PoC sample — increasing the likelihood of exploitation once the sample is public.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
