HIGH

CVE-2020-9715

Adobe Acrobat Dc 2020-08-19 CVSS v3.1
CVSS
7.8
KEV

Description

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .

Summary dbcve.org

A use-after-free vulnerability exists in Adobe Acrobat and Reader. This memory corruption issue allows an attacker to potentially execute arbitrary code by exploiting the freed memory that the application still references.

Mitigation

Apply the security updates provided by Adobe for the affected versions (2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, 2015.006.30523 and earlier).

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

48.6%
Probability of exploitation in next 30 days
98.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE