Race condition in Adobe Reader and Adobe Acrobat - CVE-2020-24428
Published: November 3, 2020
Vulnerability identifier: #VU48130
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-24428
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition. A local user can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.
Affected software
Adobe Reader
Adobe Acrobat
Adobe Acrobat
How to mitigate CVE-2020-24428
Install updates from vendor's website.
Adobe Reader - addressed in versions 17.011.30180, 20.001.30010, 20.013.20064
Adobe Acrobat - addressed in versions 17.011.30180, 20.001.30010, 20.013.20064
Adobe Acrobat - addressed in versions 17.011.30180, 20.001.30010, 20.013.20064