ZeroHour

CVE-2020-9715

KEV PoC mass1

Use-After-Free Code Execution Flaw in Adobe Acrobat

CISA: Adobe Acrobat Use-After-Free Vulnerability

CVSS 3.1
7.8 high
EPSS
49%p99
Published
()
KEV added
AI analysis

Adobe Acrobat contains a use-after-free memory-corruption flaw (CWE-416) that can lead to arbitrary code execution. The condition is triggered when the application processes specially crafted PDF content, freeing memory that is later reused, typically when a user opens a malicious PDF file. A successful exploit lets an attacker run code in the context of the current user, potentially enabling malware installation or further compromise of the workstation. Any environment running an unpatched version of Adobe Acrobat is affected, particularly fleets still on legacy or unmanaged builds. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2026-04-13, confirming exploitation in the wild; its 48.6% EPSS score (99th percentile) signals a high likelihood of near-term exploitation, while no public proof-of-concept is known and ransomware association is unconfirmed.

What to do: Update Adobe Acrobat to the latest release available from Adobe; the fix shipped in Adobe's 2020 security updates, so any installation not updated since then remains vulnerable. Because the flaw is now in the CISA KEV catalog, inventory installed Acrobat versions across the estate and treat unpatched hosts as actively targeted, following BOD 22-01 guidance for federal systems. As an interim mitigation, restrict opening of untrusted PDFs and use Acrobat's protected/preview mode until patching is complete.

Affected
Adobe Acrobat
Estimated exposure
masshundreds of millions of desktop installations worldwide (dominant PDF-viewer installed base) — Adobe Acrobat/Reader is among the most widely deployed desktop applications with a reported installed base in the hundreds of millions, so exposure is at global deployment scale, bounded only by patch status and whether users open…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .

CISA Known Exploited Vulnerability
Affected
Adobe Acrobat
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
adobe
Products
acrobat dc, acrobat reader dc
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news