CVE-2024-49535: Adobe Acrobat
Medium severity, CVSS 6.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that allows an attacker to provide malicious XML input containing a reference to an external entity, potentially leading to unauthorized read access outside the Acrobat sandbox. Exploitation of this issue requires user interaction in that a victim must process a malicious XML document.
Affected products
- Adobe Acrobat: from 20.001.30002, before 20.005.30748 (fixed in 20.005.30748); from 24.0.0, before 24.001.30225 (fixed in 24.001.30225)
- Adobe Acrobat DC: before 24.005.20320 (fixed in 24.005.20320)
- Adobe Acrobat Reader: from 20.001.30002, before 20.005.30748 (fixed in 20.005.30748)
- Adobe Acrobat Reader DC: before 24.005.20320 (fixed in 24.005.20320)
Published 2024-12-10. Last modified 2026-06-17.