CVE-2020-24438 is a use-after-free vulnerability affecting Adobe Acrobat Reader DC versions 2020.012.20048 and earlier, 2020.001.30005 and earlier, and 2017.011.30175 and earlier, potentially leading to a memory address leak. This vulnerability has a low CVSS score of 3.3, requiring user interaction (opening a malicious file) for exploitation, and its primary impact is a memory address leak, not data integrity or availability. There is no evidence of active exploitation (not in KEV), no public exploit code (Metasploit, Nuclei, ExploitDB), and limited community discussion or media coverage, indicating low current threat activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 20.001.30005CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:* | ||
<= 17.011.30175CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
<= 20.012.20048CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
<= 20.001.30005CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:* | ||
<= 17.011.30175CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.