CVE-2020-24439: Acrobat Reader DC for macOS Signature Validation Bypass
Acrobat Reader DC for macOS versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a security feature bypass. While the practical security impact is minimal, a defense-in-depth fix has been implemented to further harden the Adobe Reader update process.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-24439?
The severity of CVE-2020-24439 is considered minimal as it is a security feature bypass.
How does CVE-2020-24439 affect Adobe Acrobat products?
CVE-2020-24439 affects multiple versions of Adobe Acrobat Reader DC and Acrobat DC for macOS.
What versions of Acrobat are affected by CVE-2020-24439?
Versions 2020.012.20048 and earlier, 2020.001.30005 and earlier, and 2017.011.30175 and earlier are affected by CVE-2020-24439.
Is there a fix for CVE-2020-24439?
Yes, Adobe has implemented a defense-in-depth fix for CVE-2020-24439 to further harden the affected software.
Can CVE-2020-24439 affect user data?
The practical security impact of CVE-2020-24439 on user data is minimal.