CVE-2020-9715: high-severity vulnerability in Adobe Acrobat and Reader
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Adobe Acrobat and Reader have a use-after-free flaw that allows attackers to run malicious code by crafting a specially designed PDF file. This flaw affects multiple versions and can completely compromise your computer.
Use-after-free vulnerability in Adobe Acrobat/Reader allows remote code execution via maliciously crafted PDF files. The vulnerability exists in memory management where freed objects are accessed, and successful exploitation requires user interaction to open the malicious document.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.