Avisos de segurança da Zscaler
Zscaler protects against 6 new vulnerabilities for Adobe Acrobat and Reader
Zscaler, working with Microsoft through their MAPP program, has proactively deployed protection for the following 6 vulnerability included in the December 2024 Adobe security bulletins. Zscaler will continue to monitor exploits associated with all vulnerabilities in the December release and deploy additional protections, as necessary.
APSB24-92 – Security updates available for Adobe Acrobat and Reader.
Adobe has released security updates for Adobe Acrobat and Reader for Windows and macOS. These updates address critical and important vulnerabilities. Successful exploitation could lead to arbitrary code execution, memory leak and application denial-of-service.
Affected Software
- Acrobat DC Continuous 24.005.20307 and earlier versions for Windows & macOS
- Acrobat Reader DC Continuous 24.005.20307 and earlier versions for Windows & macOS
- Acrobat 2024 Classic 2024 24.001.30213 and earlier versions for Windows & 24.001.30193 and earlier versions for macOS
- Acrobat 2020 Classic 2020 20.005.30730 and earlier versions for Windows & 20.005.30710 and earlier versions for macOS
- Acrobat Reader 2020 Classic 2020 20.005.30730 and earlier versions for Windows & 20.005.30710 and earlier versions for macOS
CVE-2024-49530 – Use After Free vulnerability leading to Arbitrary code execution.
Severity: Critical
Subscription Required
- Advanced Threat Protection
- Advanced Cloud Sandbox
CVE-2024-49531 – NULL Pointer Dereference vulnerability leading to Application denial-of-service.
Severity: Important
Subscription Required
- Advanced Threat Protection
- Advanced Cloud Sandbox
CVE-2024-49532 – Out-of-bounds Read vulnerability leading to Memory leak.
Severity: Important
Subscription Required
- Advanced Threat Protection
- Advanced Cloud Sandbox
CVE-2024-49533 – Out-of-bounds Read vulnerability leading to Memory Leak.
Severity: Important
Subscription Required
- Advanced Threat Protection
- Advanced Cloud Sandbox
CVE-2024-49534 – Out-of-bounds Read vulnerability leading to Memory Leak.
Severity: Important
Subscription Required
- Advanced Threat Protection
- Advanced Cloud Sandbox
CVE-2024-49535 – Improper Restriction of XML External Entity Reference (‘XXE’) vulnerability leading to Arbitrary code execution.
Severity: Critical
Subscription Required
- Advanced Threat Protection
- Advanced Cloud Sandbox