CVE-2020-9715highunder attackCWE-416

CVE-2020-9715: high-severity vulnerability in Adobe Acrobat and Reader

Published · Updated

83Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 7.8epss 49%
from disclosure to weapon509 days
Published on NVDAug 19
1st PoC+509d
CISA KEV+2063d
exploitation probability
49%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
4 public exploit(s)
Action required by CISAfederal deadline: 2026-04-27

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

Adobe Acrobat and Reader have a use-after-free flaw that allows attackers to run malicious code by crafting a specially designed PDF file. This flaw affects multiple versions and can completely compromise your computer.

Technical detail

Use-after-free vulnerability in Adobe Acrobat/Reader allows remote code execution via maliciously crafted PDF files. The vulnerability exists in memory management where freed objects are accessed, and successful exploitation requires user interaction to open the malicious document.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.