Advisory

Adobe releases May 2024 fixes for critical issues in Reader, Acrobat, Illustrator and other products

Take action: Start by updating your Acrobat and Reader as a high priority. Then review the rest of the advisory to check which products you are using. Sadly, almost all of them have a critical patch that requires updating. The fortunate item is that patching is not difficult, these are client based programs.


Learn More

Adobe has released a security update as part of its 2024 May Patch Tuesday, addressing a total of 35 vulnerabilities across multiple products. This update addresses issues in Adobe Acrobat and Reader, Adobe Illustrator, Adobe Substance 3D Painter and Designer, Adobe Aero, Adobe Animate, Adobe FrameMaker, and Adobe Dreamweaver.

The update patched 9 critical vulnerabilities in Adobe Acrobat and Reader, detailed under APSB24-29. These vulnerabilities, if exploited, could lead to code execution attacks. The identified vulnerabilities are:

  • CVE-2024-30284 (CVSS score 7.8)
  • CVE-2024-30310 (CVSS score 7.8)
  • CVE-2024-34094 to CVE-2024-34100 (CVSS score 7.8)

 Other patched vulnerabilities in Reader/Acrobat are of a lower severity (CVSS score 5.5 or lower)

  • CVE-2024-30311
  • CVE-2024-30312
  • CVE-2024-34101

These issues impact Acrobat and Reader versions 24.002.20736 and earlier, and 20.005.30574 and earlier on Windows and MacOS

Other patched vulnerabilities

Adobe has stated that there are currently no known exploits in the wild for these vulnerabilities but is emphasizing the importance of updating affected software.

Adobe releases May 2024 fixes for critical issues in Reader, Acrobat, Illustrator and other products