PT-2020-5010 · Adobe · Acrobat+1
Mark Vincent Yason
+1
·
Published
2020-11-03
·
Updated
2021-09-08
·
CVE-2020-24438
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Acrobat Reader DC versions 2017.011.30175 through 2020.012.20048
Adobe Acrobat versions (affected versions not specified)
Description
The issue is related to a use-after-free vulnerability that could result in a memory address leak. Exploitation of this issue requires user interaction, where a victim must open a malicious file. This could allow a remote attacker to disclose protected information using a specially crafted file.
Recommendations
For Adobe Acrobat Reader DC versions 2017.011.30175 through 2020.012.20048, update to a version later than 2020.012.20048 to resolve the issue.
For Adobe Acrobat, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acrobat
Acrobat Reader