CVE-2020-3754 describes a critical buffer error vulnerability in multiple versions of Adobe Acrobat and Reader, affecting products across Adobe, Apple, and Microsoft platforms. This vulnerability carries a CVSS score of 9.8 (CRITICAL) due to its network-exploitable nature, low attack complexity, and potential for arbitrary code execution with high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV: No) and no publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.006.30060, <= 15.006.30508CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 15.008.20082, <= 19.021.20061CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 15.006.30060, <= 15.006.30508CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* | ||
>= 15.008.20082, <= 19.021.20061CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* | ||
>= 17.011.30059, <= 17.011.30156CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.