CVE-2024-20709

MEDIUM

Acrobat Reader T5 (MSFT Edge) <120.0.2210.91 - DoS

Title source: llm
STIX 2.1

Description

Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 44.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
adobe/acrobat < 120.0.2210.91
microsoft/edge_chromium < 120.0.2210.133
Published Jan 15, 2024
Tracked Since Feb 18, 2026