First published: Tue Nov 03 2020(Updated: )
Acrobat Reader DC for macOS versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a security feature bypass. While the practical security impact is minimal, a defense-in-depth fix has been implemented to further harden the Adobe Reader update process.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | <=20.001.30005 | |
Adobe Acrobat Reader DC | <=17.011.30175 | |
Adobe Acrobat Reader DC | <=20.012.20048 | |
Adobe Acrobat Reader Notification Manager | <=20.001.30005 | |
Adobe Acrobat Reader | <=17.011.30175 | |
Adobe Acrobat Reader | <=20.012.20048 | |
macOS | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-24439 is considered minimal as it is a security feature bypass.
CVE-2020-24439 affects multiple versions of Adobe Acrobat Reader DC and Acrobat DC for macOS.
Versions 2020.012.20048 and earlier, 2020.001.30005 and earlier, and 2017.011.30175 and earlier are affected by CVE-2020-24439.
Yes, Adobe has implemented a defense-in-depth fix for CVE-2020-24439 to further harden the affected software.
The practical security impact of CVE-2020-24439 on user data is minimal.