CyberzSOC

Publication detail
← Back to advisories & guidance

2024-022: Vulnerabilities in Adobe products ↗ source

February 29, 2024 CERT-EU Advisory

Summary

If exploited, the vulnerabilities would allow an attacker to cause remote arbitrary code execution, remote denial of service, remote code injection or disclosure of sensitive information. Among all the fixed vulnerabilities, the critical ones, with CVSS scores ranging from 7.8 to 9.1 If exploited, these critical vulnerabilities could lead to arbitrary code execution. CERT-EU strongly recommends updating software installations to the latest versions by following the instructions given by the vendor [1,2].

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-20719 9.1 Critical Adobe Adobe Commerce Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abus…
CVE-2024-20720 9.1 Critical Adobe Adobe Commerce Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command…
CVE-2024-20726 7.8 High Adobe Acrobat Reader Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary co…
CVE-2024-20727 7.8 High Adobe Acrobat Reader Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary co…
CVE-2024-20728 7.8 High Adobe Acrobat Reader Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary co…
CVE-2024-20729 7.8 High Adobe Acrobat Reader Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code exe…
CVE-2024-20730 7.8 High Adobe Acrobat Reader Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in a…
CVE-2024-20731 7.8 High Adobe Acrobat Reader Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code exe…
CVE-2024-20765 7.8 High Adobe Acrobat Reader Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code exe…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.