Acrobat out-of-bounds and Foxit use-after-free PDF reader vulnerabilities found
ID: 93441641-495a-5ff8-8f88-ea49e9e3826b
STIX ID: report--93441641-495a-5ff8-8f88-ea49e9e3826b
Feed Name: Cisco Talos
Cisco Talos reported three out-of-bounds read vulnerabilities in Adobe Acrobat Reader (CVE-2024-49534, CVE-2024-49533, CVE-2024-49532) triggered by specially crafted font files, and two use-after-free vulnerabilities in Foxit Reader (CVE-2024-49576, CVE-2024-47810) exploitable via malicious JavaScript in PDFs or via the browser extension. These issues could lead to sensitive information disclosure, memory corruption, and arbitrary code execution, and have been patched in Adobe Acrobat Reader 24.005.20320 and Foxit PDF Editor 12.1.9/11.2.12; Snort rules are available for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
