Acrobat Reader versions 20.005.30636, 24.002.21005, 24.001.30159, 20.005.30655, 24.002.20965, 24.002.20964, 24.001.30123, 24.003.20054 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary code execution. This vulnerability arises when the timing of actions changes the state of a resource between the checking of a condition and the use of the resource, allowing an attacker to manipulate the resource in a harmful way. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
2024-08-14T15:15:24.960
2024-11-21T09:27:39.373
Modified
CVSSv3.1: 7.0 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | adobe | acrobat | < 20.005.30655 | Yes |
| Application | adobe | acrobat | < 24.001.30159 | Yes |
| Application | adobe | acrobat_dc | < 24.002.21005 | Yes |
| Application | adobe | acrobat_reader | < 20.005.30655 | Yes |
| Application | adobe | acrobat_reader_dc | < 24.002.21005 | Yes |
| Operating System | apple | macos | - | No |
| Operating System | microsoft | windows | - | No |