Adobe patches critical zero-day that was exploited for months

April 14, 20262 min read2 sources
Share:
Adobe patches critical zero-day that was exploited for months

Adobe has released an emergency security update for a critical vulnerability in its Acrobat and Reader software that attackers have been actively exploiting for at least four months. The flaw, tracked as CVE-2024-34097, could allow for arbitrary code execution if a user opens a maliciously crafted PDF file.

The vulnerability affects multiple versions of Adobe Acrobat and Reader for both Windows and macOS, including Acrobat DC, Acrobat Reader DC, Acrobat 2020, and Acrobat Reader 2020. According to Adobe's security bulletin, the company is aware that this flaw "has been exploited in the wild in limited attacks."

The zero-day was discovered and reported to Adobe by security researchers at Mandiant. A report from Dark Reading states that threat actors had been leveraging the vulnerability for a minimum of four months before the patch was issued on May 14. This extended period of undetected exploitation gave attackers a significant window to compromise targets.

Successful exploitation of CVE-2024-34097 grants an attacker the ability to execute code with the same privileges as the logged-in user. This could lead to a complete system takeover, enabling the installation of malware like ransomware or spyware, data theft, and further movement within a compromised network.

Given the active exploitation of this vulnerability, users and system administrators are strongly advised to apply the patches detailed in Adobe Security Bulletin APSB24-29 immediately. The widespread use of PDF documents makes this flaw a significant threat, as attackers often use them as a primary vector for initial access in targeted phishing campaigns.

Share:

// SOURCES

// RELATED

Most 'AI SOCs' are just faster triage, and that's not enough

Many AI security tools only speed up alert analysis, failing to reduce analyst workload. Experts argue real gains require AI that automates response a

2 min readApr 17

ZionSiphon malware designed to sabotage water treatment systems

A new proof-of-concept malware, ZionSiphon, demonstrates how attackers can sabotage water treatment plants by manipulating industrial control systems.

2 min readApr 17

ThreatsDay bulletin: A deep dive into the Defender 0-day, SonicWall attacks, and a 17-year-old Excel flaw

This week’s threat bulletin is a heavy one. We analyze the critical Microsoft Defender 0-day, a massive SonicWall brute-force campaign, and a 17-year-

6 min readApr 17

Microsoft Defender's 'RedSun' zero-day: A researcher's protest and a threat to Windows systems

A researcher's protest exposed a critical zero-day in Microsoft Defender, allowing attackers full system control. Here's the technical breakdown and h

7 min readApr 17