CVE-2020-9715
KEV PoC mass1Use-After-Free Code Execution Flaw in Adobe Acrobat
CISA: Adobe Acrobat Use-After-Free Vulnerability
Adobe Acrobat contains a use-after-free memory-corruption flaw (CWE-416) that can lead to arbitrary code execution. The condition is triggered when the application processes specially crafted PDF content, freeing memory that is later reused, typically when a user opens a malicious PDF file. A successful exploit lets an attacker run code in the context of the current user, potentially enabling malware installation or further compromise of the workstation. Any environment running an unpatched version of Adobe Acrobat is affected, particularly fleets still on legacy or unmanaged builds. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2026-04-13, confirming exploitation in the wild; its 48.6% EPSS score (99th percentile) signals a high likelihood of near-term exploitation, while no public proof-of-concept is known and ransomware association is unconfirmed.
What to do: Update Adobe Acrobat to the latest release available from Adobe; the fix shipped in Adobe's 2020 security updates, so any installation not updated since then remains vulnerable. Because the flaw is now in the CISA KEV catalog, inventory installed Acrobat versions across the estate and treat unpatched hosts as actively targeted, following BOD 22-01 guidance for federal systems. As an interim mitigation, restrict opening of untrusted PDFs and use Acrobat's protected/preview mode until patching is complete.
| Adobe Acrobat | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .
- Affected
- Adobe Acrobat
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- adobe
- Products
- acrobat dc, acrobat reader dc
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H