First published: Tue Feb 13 2024(Updated: )
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2024-20736.
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat DC |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-24-166 is classified as critical due to its potential for remote information disclosure.
To fix ZDI-24-166, update Adobe Acrobat Pro DC to the latest version as recommended by Adobe.
ZDI-24-166 affects installations of Adobe Acrobat Pro DC that have not been updated to address the vulnerability.
ZDI-24-166 can be exploited by remote attackers requiring user interaction, such as visiting a malicious page or opening a harmful file.
ZDI-24-166 allows remote attackers to disclose sensitive information from affected installations of Adobe Acrobat Pro DC.