First published: Tue Nov 03 2020(Updated: )
Acrobat Pro DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by an out-of-bounds write vulnerability that could result in writing past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. This vulnerability requires user interaction to exploit in that the victim must open a malicious document.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Pro DC | ||
Adobe Acrobat Reader | <=20.001.30005 | |
Adobe Acrobat Dc | <=17.011.30175 | |
Adobe Acrobat Dc | <=20.012.20048 | |
Adobe Acrobat Reader | <=20.001.30005 | |
Adobe Acrobat Reader DC | <=17.011.30175 | |
Adobe Acrobat Reader DC | <=20.012.20048 | |
Apple macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24436 is a vulnerability in Adobe Acrobat Pro DC that allows remote attackers to execute arbitrary code.
CVE-2020-24436 exploits an out-of-bounds write vulnerability during the exporting of PDF files.
CVE-2020-24436 has a severity rating of 7.8 (High).
Adobe Acrobat Pro DC versions up to and including 20.001.30005 are affected.
Make sure to update Adobe Acrobat Pro DC to version 20.001.30006 or later to fix CVE-2020-24436.