CVE-2024-49535

MEDIUM

Acrobat Reader <24.005.20307 - XSS

Title source: llm
STIX 2.1

Description

Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that allows an attacker to provide malicious XML input containing a reference to an external entity, potentially leading to unauthorized read access outside the Acrobat sandbox. Exploitation of this issue requires user interaction in that a victim must process a malicious XML document.

Scores

CVSS v3 6.3
EPSS 0.0010
EPSS Percentile 27.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (4)
adobe/acrobat 20.001.30002 - 20.005.30748
adobe/acrobat_dc < 24.005.20320
adobe/acrobat_reader 20.001.30002 - 20.005.30748
adobe/acrobat_reader_dc < 24.005.20320
Published Dec 10, 2024
Tracked Since Feb 18, 2026