PT-2024-1752 · Adobe · Acrobat Reader+3

Published

2024-02-13

·

Updated

2024-03-01

·

CVE-2024-20733

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier Adobe Acrobat 2020 Adobe Acrobat Reader 2020 Adobe Acrobat Document Cloud Adobe Acrobat Reader Document Cloud
Description The issue is related to an Improper Input Validation vulnerability that could lead to an application denial-of-service. An attacker could leverage this vulnerability to cause the application to crash, resulting in a denial of service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Recommendations For Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier, update to a version that fixes the Improper Input Validation vulnerability. For Adobe Acrobat 2020, Adobe Acrobat Reader 2020, Adobe Acrobat Document Cloud, and Adobe Acrobat Reader Document Cloud, update to a version that fixes the Improper Input Validation vulnerability. As a temporary workaround, consider avoiding the opening of malicious files to minimize the risk of exploitation.

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-01463
CVE-2024-20733

Affected Products

Acrobat Reader
Acrobat
Acrobat Document Cloud
Adobe Acrobat Reader Document Cloud