CVE-2020-24436
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
Acrobat Pro DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by an out-of-bounds write vulnerability that could result in writing past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. This vulnerability requires user interaction to exploit in that the victim must open a malicious document.
Affected (6)
Products: Adobe: Acrobat, Acrobat Dc, Acrobat Reader, Acrobat Reader Dc
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 20.001.30005 | |
| Up to 17.011.30175 | |
| Up to 20.001.30005 | |
| Up to 17.011.30175 |
| Running on/with | Platform Versions |
|---|---|
Apple Macos | All versions |
Microsoft Windows | All versions |
References (4)
Source: psirt@adobe.com
Vendor Advisory
Source: psirt@adobe.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Timeline
No history available yet.