Vulnerability in Acrobat Reader could lead to remote code execution; Microsoft patches information disclosure issue in Windows API
ID: 4afad064-f38d-5c6a-a3e3-7af27ff14376
STIX ID: report--4afad064-f38d-5c6a-a3e3-7af27ff14376
Feed Name: Cisco Talos
Cisco Talos disclosed two recently fixed vulnerabilities: CVE-2024-38257, an information disclosure in the Microsoft Windows AllJoyn API that can expose uninitialized memory and requires no user privileges or interaction (assessed as "less likely" to be exploited), and CVE-2024-39420, a time-of-check/time-of-use use-after-free race condition in Adobe Acrobat Reader triggered by malicious PDF-embedded JavaScript that can lead to memory corruption and potentially arbitrary code execution; Talos provides advisory details and Snort rule coverage and notes Microsoft has issued patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
