Vulnerability record · CVE-2020-9715 · published 19 August 2020
CVE-2020-9715: Adobe Acrobat and Reader use-after-free allows code execution
Adobe · Acrobat Dc
Adobe Acrobat and Reader contain a use-after-free (CWE-416) flaw affecting versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier. Successful exploitation can lead to arbitrary code execution in the context of the affected application. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it is a confirmed target in real-world attacks.
Description
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityConfirmed exploitation via CISA KEV plus very high EPSS probability, with arbitrary code execution impact, though it requires local user interaction to trigger.
What it is
Adobe Acrobat and Reader contain a use-after-free (CWE-416) flaw affecting versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier. Successful exploitation can lead to arbitrary code execution in the context of the affected application. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it is a confirmed target in real-world attacks.
Impact
An attacker who gets a crafted file opened can execute arbitrary code on the victim's machine, giving full control of the user's session and data. Because the vector is local with user interaction, the practical gain is code execution on the endpoint rather than remote server compromise.
Attack surface
Reached by convincing a user to open a malicious PDF or related file in Acrobat or Reader; the CVSS vector is AV:L/AC:L/PR:N/UI:R, so no privileges are needed but user interaction is required. No network-facing service is involved.
Exploitation
CVE-2020-9715 is in CISA's KEV catalog (added 2026-04-13, due 2026-04-27) and EPSS shows a 30-day probability of 0.48595 (98.8th percentile), indicating high likelihood of exploitation. Reference tags include Exploit, and no ransomware campaign use is documented.
What to do
- Apply the vendor patch per Adobe security bulletin APSB20-48 and upgrade Acrobat and Reader to a fixed release.
- If patching cannot be done immediately, follow CISA KEV required action: apply vendor mitigations or discontinue use of the affected product.
- Restrict or block untrusted PDF attachments at email and web gateways, and disable automatic opening of PDFs from untrusted sources.
- Run Acrobat and Reader with reduced privileges and enable Protected View/Protected Mode where available.
- Track KEV remediation deadlines (due 2026-04-27) and confirm all endpoints are updated.
Detection
- Monitor for Acrobat/Reader processes spawning child processes such as cmd.exe, powershell.exe, or scripting hosts, which is abnormal for normal PDF viewing.
- Alert on crashes or abnormal termination of Acrobat/Reader followed by suspicious process creation, consistent with use-after-free exploitation.
- Hunt for PDF files delivered via email or web downloads that are opened shortly before unusual child-process activity on the same host.
- Inventory Acrobat and Reader versions across endpoints and flag any still matching the affected version ranges.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-9715 to the Known Exploited Vulnerabilities catalog on 13 April 2026 as "Adobe Acrobat Use-After-Free Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 27 April 2026.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://blog.exodusintel.com/2021/04/20/analysis-of-a-use-after-free-vulnerability-in-adobe-acrobat-reader-dc/ | ExploitPatchThird Party Advisory |
| https://helpx.adobe.com/security/products/acrobat/apsb20-48.html | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-20-991/ | Third Party AdvisoryVDB Entry |
| https://blog.exodusintel.com/2021/04/20/analysis-of-a-use-after-free-vulnerability-in-adobe-acrobat-reader-dc/ | ExploitPatchThird Party Advisory |
| https://helpx.adobe.com/security/products/acrobat/apsb20-48.html | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-20-991/ | Third Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-9715 | US Government Resource |
Track CVE-2020-9715 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-9715), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.