PT-2020-5010 · Adobe · Acrobat+1

Mark Vincent Yason

+1

·

Published

2020-11-03

·

Updated

2021-09-08

·

CVE-2020-24438

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adobe Acrobat Reader DC versions 2017.011.30175 through 2020.012.20048 Adobe Acrobat versions (affected versions not specified)
Description The issue is related to a use-after-free vulnerability that could result in a memory address leak. Exploitation of this issue requires user interaction, where a victim must open a malicious file. This could allow a remote attacker to disclose protected information using a specially crafted file.
Recommendations For Adobe Acrobat Reader DC versions 2017.011.30175 through 2020.012.20048, update to a version later than 2020.012.20048 to resolve the issue. For Adobe Acrobat, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05595
CVE-2020-24438
ZDI-20-1357

Affected Products

Acrobat
Acrobat Reader