HTTP: Adobe Acrobat Reader CVE-2024-39426 Access of Memory Location After End of Buffer

This signature detects attempts to exploit a known vulnerability against Adobe Acrobat Reader. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.

Extended Description

Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Short Name
HTTP:STC:ADOBE:CVE2024-39426-BO
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Access Acrobat Adobe After Buffer CVE-2024-39426 End Location Memory Reader of
Release Date
08/30/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3737
False Positive
Unknown

Found a potential security threat?