CVE-2020-9715
published 2020-08-19CVE-2020-9715: Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free…
PriorityP183high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-04-27
Exploited in the wild
EPSS
48.44%
98.7th percentile
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat_dc | — | — |
| adobe | acrobat_dc | 15.006.30060 – 15.006.30523 | — |
| adobe | acrobat_dc | 15.008.20082 – 20.009.20074 | — |
| adobe | acrobat_dc | 17.011.30059 – 17.011.30171 | — |
| adobe | acrobat_reader_dc | — | — |
| adobe | acrobat_reader_dc | 15.006.30060 – 15.006.30523 | — |
| adobe | acrobat_reader_dc | 15.008.20082 – 20.009.20074 | — |
| adobe | acrobat_reader_dc | 17.011.30059 – 17.011.30171 | — |
| adobe | adobe_acrobat_and_reader | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect heap spray of large numbers of ArrayBuffers in Adobe Reader JavaScript context, particularly when byteLength is corrupted to 0xFFFFFFFF, indicative of CVE-2020-9715 exploitation. ↗
- →Monitor for use-after-free patterns involving Data ESObject cache stale pointer reuse in Adobe Reader/Acrobat renderer process — freed ESObject pointer remains in object cache due to ANSI/Unicode key mismatch on deletion. ↗
- →Look for ROP chain execution triggered via JSObject::setGeneric() in Adobe Reader renderer process as a code execution indicator for this exploit. ↗
- →Detect attempts to leak the load address of AcroForm.api via AcroForm text field pointer written into an ArrayBuffer object — a prerequisite step in this exploit chain. ↗
- →LFH (Low Fragmentation Heap) priming for allocation size 0x48 bytes in Adobe Reader process may indicate preparation for ESObject UAF exploitation. ↗
- ·Exploitation achieves code execution only within the renderer process (sandbox), not full system compromise directly. ↗
- ·Affected versions include Adobe Acrobat and Reader 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Acrobat Reader use after free (APSB20-48)
vuldb·2026-04-13·CVSS 7.8
CVE-2020-9715 [HIGH] Adobe Acrobat Reader use after free (APSB20-48)
A vulnerability classified as critical was found in Adobe Acrobat Reader up to 2015.006.30523/2017.011.30171/2020.001.30002/2020.009.20074. This affects an unknown function. The manipulation results in use after free.
This vulnerability is cataloged as CVE-2020-9715. The attack may be launched remotely. Furthermore, there is an exploit available.
Upgrading the affected component is advised.
GHSA
GHSA-wxg9-xx37-xj49: Adobe Acrobat and Reader versions 2020
ghsa_unreviewed·2022-05-24
CVE-2020-9715 [HIGH] CWE-416 GHSA-wxg9-xx37-xj49: Adobe Acrobat and Reader versions 2020
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .
VulnCheck
Adobe Acrobat Use-After-Free Vulnerability
vulncheck·2020·CVSS 7.8
CVE-2020-9715 [HIGH] CWE-416 Adobe Acrobat Use-After-Free Vulnerability
Adobe Acrobat Use-After-Free Vulnerability
Adobe Acrobat contains a use-after-free vulnerability that allows for code execution
Affected: Adobe Acrobat
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/70780b4e2426
Remediation Due: 2026-04-27
Project0
Project Zero RCA: CVE-2023-26369: Adobe Acrobat PDF Reader RCE when processing TTF fonts
project_zero·CVSS 7.8
CVE-2023-26369 [HIGH] Project Zero RCA: CVE-2023-26369: Adobe Acrobat PDF Reader RCE when processing TTF fonts
# CVE-2023-26369: Adobe Acrobat PDF Reader RCE when processing TTF fonts
Clement Lecigne, Google Threat Analysis Group
## The Basics
**Disclosure or Patch Date:** September, 12, 2023
**Product:** Adobe Acrobat Reader on Windows and MacOS
**Advisory:** https://helpx.adobe.com/security/products/acrobat/apsb23-34.html
**Affected Versions:** 23.003.20284 and earlier versions
**First Patched Version:** 23.006.20320
**Issue/Bug Report:** N/A
**Patch CL:** N/A (closed source)
**Bug-Introducing CL:** N/A
**Reporter(s):** Anonymous
## The Code
**Proof-of-concept:**
TTF font with the following bitmap tables.
```
EBLC :
version : 0x20000
numSizes : 0x1
[-] 0th bitmapSizeTable
indexSubTableArrayOffset : 0x38
indexTablesSize : 0x100
numberOfIndexSubTables : 0x2
colorRef : 0x0
hori : 0b f
CISA
Adobe Acrobat Use-After-Free Vulnerability
cisa·2026-04-13·CVSS 7.8
CVE-2020-9715 [HIGH] CWE-416 Adobe Acrobat Use-After-Free Vulnerability
Vulnerability: Adobe Acrobat Use-After-Free Vulnerability
Affected: Adobe Acrobat
Adobe Acrobat contains a use-after-free vulnerability that allows for code execution
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://helpx.adobe.com/security/products/acrobat/apsb20-48.html ; https://nvd.nist.gov/vuln/detail/CVE-2020-9715
Remediation Due Date: 2026-04-27
No detection rules found.
No public exploits indexed.
Hackernews
CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software
blogs_hackernews·2026-04-14·CVSS 7.8
[HIGH] CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added half a dozen security flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, citing evidence of active exploitation.
The list of vulnerabilities is as follows -
CVE-2026-21643 (CVSS score: 9.1) - An SQL injection vulnerability in Fortinet FortiClient EMS that could allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
CVE-2020-9715 (CVSS score: 7.8) - A use-after-free vulnerability in Adobe Acrobat Re
Trendmicro
CVE-2020-9715: Exploiting a Use-After-Free in Adobe Reader
blogs_trendmicro·2020-09-03·CVSS 7.8
CVE-2020-9715 [HIGH] CVE-2020-9715: Exploiting a Use-After-Free in Adobe Reader
# CVE-2020-9715: Exploiting a Use-After-Free in Adobe Reader
How to exploit a use-after-free in Adobe Reader.
By: Zero Day Initiative
2020/09/03
Read time: ( words)
Save to Folio
It’s a great feeling when you wake up in the morning to the smell of a fresh pour-over coffee and find a nice 0-day waiting for you in the queue. That’s my typical day-to-day morning at the ZDI. I won’t lie - some of the submissions can be disappointing but, on the other hand, a lot of the submissions we get are excellent.
One such example that is worthy of discussing today is an Adobe Reader submission by the great Mark Yason. The submission was composed of a detailed analysis of a Use-After-Free vulnerability along with an exploit that achieves code execution in the renderer process.
The vulnerability
Wh
Trendmicro
CVE-2020-9715: Exploiting a Use-After-Free in Adobe Reader
blogs_trendmicro·2020-09-03·CVSS 7.8
CVE-2020-9715 [HIGH] CVE-2020-9715: Exploiting a Use-After-Free in Adobe Reader
## CVE-2020-9715: Exploiting a Use-After-Free in Adobe Reader
How to exploit a use-after-free in Adobe Reader.
By: Zero Day Initiative 2020/09/03 Read time: ( words)
Save to Folio
It’s a great feeling when you wake up in the morning to the smell of a fresh pour-over coffee and find a nice 0-day waiting for you in the queue. That’s my typical day-to-day morning at the ZDI. I won’t lie - some of the submissions can be disappointing but, on the other hand, a lot of the submissions we get are excellent.
One such example that is worthy of discussing today is an Adobe Reader submission by the great Mark Yason . The submission was composed of a detailed analysis of a Use-After-Free vulnerability along with an exploit that achieves code execution in the renderer process.
The vulnerability
W
Trendmicro
CVE-2020-9715: Exploiting a Use-After-Free in Adobe Reader
blogs_trendmicro·2020-09-03·CVSS 7.8
CVE-2020-9715 [HIGH] CVE-2020-9715: Exploiting a Use-After-Free in Adobe Reader
## CVE-2020-9715: Exploiting a Use-After-Free in Adobe Reader
How to exploit a use-after-free in Adobe Reader.
By: Zero Day Initiative Sep 03, 2020 Read time: ( words)
Save to Folio
It’s a great feeling when you wake up in the morning to the smell of a fresh pour-over coffee and find a nice 0-day waiting for you in the queue. That’s my typical day-to-day morning at the ZDI. I won’t lie - some of the submissions can be disappointing but, on the other hand, a lot of the submissions we get are excellent.
One such example that is worthy of discussing today is an Adobe Reader submission by the great Mark Yason . The submission was composed of a detailed analysis of a Use-After-Free vulnerability along with an exploit that achieves code execution in the renderer process.
The vulnerability
https://blog.exodusintel.com/2021/04/20/analysis-of-a-use-after-free-vulnerability-in-adobe-acrobat-reader-dc/https://helpx.adobe.com/security/products/acrobat/apsb20-48.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-20-991/https://blog.exodusintel.com/2021/04/20/analysis-of-a-use-after-free-vulnerability-in-adobe-acrobat-reader-dc/https://helpx.adobe.com/security/products/acrobat/apsb20-48.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-20-991/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-9715
2020-08-19
Published
2026-04-13
Added to CISA KEV
Exploited in the wild