cbcvebase.
CVE-2020-24441
published 2020-11-12

CVE-2020-24441: Adobe Acrobat Reader for Android version 20.6.2 (and earlier) does not properly restrict access to directories created by the application. This could result in…

PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
2.26%
81.2th percentile
Adobe Acrobat Reader for Android version 20.6.2 (and earlier) does not properly restrict access to directories created by the application. This could result in disclosure of sensitive information stored in databases used by the application. Exploitation requires a victim to download and run a malicious application.

Affected

2 ranges
VendorProductVersion rangeFixed in
adobeacrobat_reader<= 20.6.2
adobeacrobat_readerunspecified – 20.6.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.