cbcvebase.
CVE-2020-24433
published 2020-11-05

CVE-2020-24433: Adobe Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a local privilege…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
Adobe Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a local privilege escalation vulnerability that could enable a user without administrator privileges to delete arbitrary files and potentially execute arbitrary code as SYSTEM. Exploitation of this issue requires an attacker to socially engineer a victim, or the attacker must already have some access to the environment.

Affected

7 ranges
VendorProductVersion rangeFixed in
adobeacrobat<= 20.001.30005
adobeacrobat_dc<= 17.011.30175
adobeacrobat_dc<= 20.012.20048
adobeacrobat_reader<= 20.001.30005
adobeacrobat_readerunspecified – 2017.011.30175
adobeacrobat_reader_dc<= 17.011.30175
adobeacrobat_reader_dc<= 20.012.20048