Adobe Acrobat Reader DC versions 2020.012.20048, 2020.001.30005, and 2017.011.30175 are vulnerable to local privilege escalation allowing arbitrary code execution. Learn about the impact and mitigation.
Adobe Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier), and 2017.011.30175 (and earlier) are affected by a local privilege escalation vulnerability that could allow an attacker to execute arbitrary code as SYSTEM.
Understanding CVE-2020-24433
Adobe Acrobat Reader DC Local Privilege Escalation via Installer Component
What is CVE-2020-24433?
CVE-2020-24433 is a vulnerability in Adobe Acrobat Reader DC that enables a user without administrator privileges to delete arbitrary files and potentially execute arbitrary code as SYSTEM.
The Impact of CVE-2020-24433
Technical Details of CVE-2020-24433
Adobe Acrobat Reader DC Local Privilege Escalation via Installer Component
Vulnerability Description
The vulnerability allows a non-administrator user to delete arbitrary files and potentially execute arbitrary code as SYSTEM.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Adobe Acrobat Reader DC Local Privilege Escalation via Installer Component
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates