Description
Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to spoof the identity of a signer. Exploitation of this issue requires user interaction.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Affected products
- Adobe / Acrobat 20240 – 24.001.30307 (Win), 24.001.30308 (Mac)
- Adobe / Acrobat 202424.001.30356 – 24.001.30356
- Adobe / Acrobat DC25.001.21288 – 25.001.21288
- Adobe / Acrobat DC0 – 25.001.21265
- Adobe / Acrobat Reader0 – 25.001.21265
- Adobe / Acrobat Reader DC0 – 25.001.21265
- Adobe / Acrobat Reader DC25.001.21288 – 25.001.21288
References
Updated 8m ago · 8 sources