CVE-2024-20736: ZDI-CAN-22822: Adobe Acrobat Pro DC AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability
Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Acrobat Reader/Proto a version that resolves this vulnerability.Fixed in 23.008.20470Patch ZDI-CAN-22822 - Upgrade
Upgrade
Adobe Acrobat Reader/Proto a version that resolves this vulnerability.Fixed in 20.005.30539Patch ZDI-CAN-22822
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20736?
CVE-2024-20736 is considered a critical vulnerability due to its potential for memory disclosure and bypassing security mitigations.
How do I fix CVE-2024-20736?
To fix CVE-2024-20736, update your Adobe Acrobat Reader to the latest version available.
Which versions of Adobe Acrobat Reader are affected by CVE-2024-20736?
CVE-2024-20736 affects Adobe Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier.
Can exploitation of CVE-2024-20736 lead to sensitive data exposure?
Yes, exploitation of CVE-2024-20736 could lead to the disclosure of sensitive memory.
Does CVE-2024-20736 affect both Windows and macOS?
No, CVE-2024-20736 specifically affects Adobe Acrobat on certain versions, while macOS and Windows platforms are not directly vulnerable.