HIGH
CVE-2020-9715
CVSS
7.8
KEV
Description
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .
Summary dbcve.org
A use-after-free vulnerability exists in Adobe Acrobat and Reader. This memory corruption issue allows an attacker to potentially execute arbitrary code by exploiting the freed memory that the application still references.
Mitigation
Apply the security updates provided by Adobe for the affected versions (2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, 2015.006.30523 and earlier).
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
48.6%
Probability of exploitation in next 30 days
98.8th percentile
References
https://blog.exodusintel.com/2021/04/20/analysis-of-a-use-after-free-vulnerability-in-adobe-acrobat-reader-dc/
Exploit, Patch, Third Party Advisory
https://helpx.adobe.com/security/products/acrobat/apsb20-48.html
Vendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-991/
Third Party Advisory, VDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-9715
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.