CVE-2020-24435
published 2020-11-05CVE-2020-24435: Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a heap-based buffer…
PriorityP357high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
51.28%
98.8th percentile
Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a heap-based buffer overflow vulnerability in the submitForm function, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted .pdf file in Acrobat Reader.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | <= 20.001.30005 | — |
| adobe | acrobat_dc | <= 17.011.30175 | — |
| adobe | acrobat_dc | <= 20.012.20048 | — |
| adobe | acrobat_reader | <= 20.001.30005 | — |
| adobe | acrobat_reader | unspecified – 2017.011.30175 | — |
| adobe | acrobat_reader_dc | <= 17.011.30175 | — |
| adobe | acrobat_reader_dc | <= 20.012.20048 | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
53563-53564, 55842-55843
- →Trigger vector is a crafted PDF file containing specific JavaScript code targeting the submitForm function; detect PDF files with embedded JavaScript invoking submitForm that may cause out-of-bounds memory access. ↗
- →Exploitation can also be triggered via a malicious web page (e.g., through the Acrobat browser plugin), so monitor browser-spawned Acrobat Reader processes loading remote PDF content. ↗
- →The vulnerability was re-introduced after a prior patch (TALOS-2020-1031); ensure detection logic covers regression scenarios in Adobe Acrobat Reader DC versions up to and including 2020.012.20043. ↗
- ·Snort rules 53563-53564 and 55842-55843 are subject to change; always pull the latest rule versions from Firepower Management Center or Snort.org. ↗
- ·Confirmed affected version is 2020.012.20043; versions 2020.012.20048 and earlier, 2020.001.30005 and earlier, and 2017.011.30175 and earlier are all in scope. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Multiple JavaScript vulnerabilities in Adobe Acrobat Reader
blogs_talos·2020-11-05·CVSS 7.8
[HIGH] Vulnerability Spotlight: Multiple JavaScript vulnerabilities in Adobe Acrobat Reader
## Vulnerability Spotlight: Multiple JavaScript vulnerabilities in Adobe Acrobat Reader
Aleksandar Nikolic of Cisco Talos discovered these vulnerabilities. Blog by Joe Marshall
Cisco Talos recently discovered an heap buffer overflow and a use after free vulnerability in Adobe Acrobat Reader. Adobe Acrobat Reader is one of the most popular and feature-rich PDF readers on the market. It has a large user base and is usually a default PDF reader on systems. It also integrates into
web browsers as a plugin for rendering PDFs. As such, tricking a user into visiting a malicious web page or sending a specially crafted email attachment can be enough to trigger these vulnerabilities.
In accordance with our coordinated disclosure policy, Cisco Talos worked with Adobe to ensure that these issues a
Talos
Vulnerability Spotlight: Multiple JavaScript vulnerabilities in Adobe Acrobat Reader
blogs_talos·2020-11-05·CVSS 7.8
[HIGH] Vulnerability Spotlight: Multiple JavaScript vulnerabilities in Adobe Acrobat Reader
Aleksandar Nikolic of Cisco Talos discovered these vulnerabilities. Blog by Joe Marshall
> >
> >
Cisco Talos recently discovered an heap buffer overflow and a use after free vulnerability in Adobe Acrobat Reader. Adobe Acrobat Reader is one of the most popular and feature-rich PDF readers on the market. It has a large user base and is usually a default PDF reader on systems. It also integrates into
web browsers as a plugin for rendering PDFs. As such, tricking a user into visiting a malicious web page or sending a specially crafted email attachment can be enough to trigger these vulnerabilities.
In accordance with our coordinated disclosure policy, Cisco Talos worked with Adobe to ensure that these issues are resolved and that an update is available for affected customers.
### Vulner
2020-11-05
Published