Show plain JSON{"dataType": "CVE_RECORD", "containers": {"adp": [{"title": "CISA ADP Vulnrichment", "metrics": [{"other": {"type": "ssvc", "content": {"id": "CVE-2024-39422", "role": "CISA Coordinator", "options": [{"Exploitation": "none"}, {"Automatable": "no"}, {"Technical Impact": "total"}], "version": "2.0.3", "timestamp": "2024-08-14T15:52:07.707553Z"}}}], "affected": [{"cpes": ["cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:*:windows:*:*"], "vendor": "adobe", "product": "acrobat_dc", "versions": [{"status": "affected", "version": "0", "versionType": "semver", "lessThanOrEqual": "24.002.20991"}], "defaultStatus": "affected"}, {"cpes": ["cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:*:macos:*:*"], "vendor": "adobe", "product": "acrobat_dc", "versions": [{"status": "affected", "version": "0", "versionType": "semver", "lessThanOrEqual": "24.002.20964"}], "defaultStatus": "affected"}, {"cpes": ["cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*"], "vendor": "adobe", "product": "acrobat", "versions": [{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "24.001.30123"}], "defaultStatus": "affected"}, {"cpes": ["cpe:2.3:a:adobe:acrobat:*:*:*:*:*:windows:*:*"], "vendor": "adobe", "product": "acrobat", "versions": [{"status": "affected", "version": "0", "versionType": "semver", "lessThanOrEqual": "24.001.30123"}, {"status": "affected", "version": "20.0", "versionType": "semver", "lessThanOrEqual": "20.005.30636"}], "defaultStatus": "affected"}, {"cpes": ["cpe:2.3:a:adobe:acrobat:*:*:*:*:*:macos:*:*"], "vendor": "adobe", "product": "acrobat", "versions": [{"status": "affected", "version": "0", "versionType": "semver", "lessThanOrEqual": "24.001.30123"}, {"status": "affected", "version": "20.0", "versionType": "semver", "lessThanOrEqual": "20.005.30635"}], "defaultStatus": "affected"}, {"cpes": ["cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:windows:*:*"], "vendor": "adobe", "product": "acrobat_reader", "versions": [{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "20.005.30636"}], "defaultStatus": "affected"}, {"cpes": ["cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:macos:*:*"], "vendor": "adobe", "product": "acrobat_reader", "versions": [{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "20.005.30635"}], "defaultStatus": "affected"}, {"cpes": ["cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:macos:*:*"], "vendor": "adobe", "product": "acrobat_reader_dc", "versions": [{"status": "affected", "version": "0", "versionType": "semver", "lessThanOrEqual": "24.002.20964"}], "defaultStatus": "affected"}, {"cpes": ["cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:windows:*:*"], "vendor": "adobe", "product": "acrobat_reader_dc", "versions": [{"status": "affected", "version": "0", "versionType": "semver", "lessThanOrEqual": "24.002.20991"}], "defaultStatus": "affected"}], "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-08-14T15:54:55.932Z"}}], "cna": {"title": "ZDI-CAN-24090: New Vulnerability Report - Use-after-free remote code execution vulnerability in Adobe Acrobat Reader DC", "source": {"discovery": "EXTERNAL"}, "metrics": [{"format": "CVSS", "cvssV3_1": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.8, "attackVector": "LOCAL", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "modifiedScope": "NOT_DEFINED", "temporalScore": 7.8, "integrityImpact": "HIGH", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "remediationLevel": "NOT_DEFINED", "reportConfidence": "NOT_DEFINED", "temporalSeverity": "HIGH", "availabilityImpact": "HIGH", "environmentalScore": 7.8, "privilegesRequired": "NONE", "exploitCodeMaturity": "NOT_DEFINED", "integrityRequirement": "NOT_DEFINED", "modifiedAttackVector": "LOCAL", "confidentialityImpact": "HIGH", "environmentalSeverity": "HIGH", "availabilityRequirement": "NOT_DEFINED", "modifiedIntegrityImpact": "HIGH", "modifiedUserInteraction": "REQUIRED", "modifiedAttackComplexity": "LOW", "confidentialityRequirement": "NOT_DEFINED", "modifiedAvailabilityImpact": "HIGH", "modifiedPrivilegesRequired": "NONE", "modifiedConfidentialityImpact": "HIGH"}, "scenarios": [{"lang": "en", "value": "GENERAL"}]}], "affected": [{"vendor": "Adobe", "product": "Acrobat Reader", "versions": [{"status": "affected", "version": "0", "versionType": "semver", "lessThanOrEqual": "24.001.30123"}], "defaultStatus": "affected"}], "datePublic": "2024-08-13T17:00:00.000Z", "references": [{"url": "https://helpx.adobe.com/security/products/acrobat/apsb24-57.html", "tags": ["vendor-advisory"]}], "descriptions": [{"lang": "en", "value": "Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."}], "problemTypes": [{"descriptions": [{"lang": "en", "type": "CWE", "cweId": "CWE-416", "description": "Use After Free (CWE-416)"}]}], "providerMetadata": {"orgId": "078d4453-3bcd-4900-85e6-15281da43538", "shortName": "adobe", "dateUpdated": "2024-08-14T15:07:31.068Z"}}}, "cveMetadata": {"cveId": "CVE-2024-39422", "state": "PUBLISHED", "dateUpdated": "2024-08-14T15:55:27.119Z", "dateReserved": "2024-06-24T20:32:06.595Z", "assignerOrgId": "078d4453-3bcd-4900-85e6-15281da43538", "datePublished": "2024-08-14T15:07:31.068Z", "assignerShortName": "adobe"}, "dataVersion": "5.1"}