CVE-2020-24433: Adobe Acrobat Reader DC Local Privilege Escalation via Installer Component

Published Nov 5, 2020
·
Updated

Adobe Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a local privilege escalation vulnerability that could enable a user without administrator privileges to delete arbitrary files and potentially execute arbitrary code as SYSTEM. Exploitation of this issue requires an attacker to socially engineer a victim, or the attacker must already have some access to the environment.

Affected Software

8 affected components
Adobe Acrobat<=20.001.30005
Adobe Acrobat DC<=17.011.30175
Adobe Acrobat DC<=20.012.20048
Adobe Acrobat Reader<=20.001.30005
Adobe Acrobat Reader DC<=17.011.30175
Adobe Acrobat Reader DC<=20.012.20048
Apple macOS
Microsoft Windows

Event History

Nov 5, 2020
CVE Published
via MITRE·07:32 PM
Data Sourced
via MITRE·07:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2020-24433?

CVE-2020-24433 is classified as a local privilege escalation vulnerability.

2

How do I fix CVE-2020-24433?

To mitigate CVE-2020-24433, upgrade Adobe Acrobat Reader DC to the latest version available.

3

Which versions of Adobe Acrobat are affected by CVE-2020-24433?

CVE-2020-24433 affects Adobe Acrobat Reader DC versions 2020.012.20048 and earlier, 2020.001.30005 and earlier, and Adobe Acrobat DC versions 2017.011.30175 and earlier.

4

Can non-administrator users exploit CVE-2020-24433?

Yes, CVE-2020-24433 allows non-administrator users to escalate their privileges and potentially delete arbitrary files.

5

Is CVE-2020-24433 specific to Adobe software on particular operating systems?

CVE-2020-24433 is primarily associated with specific versions of Adobe Acrobat on Windows and does not affect the Apple macOS versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203