CVE-2020-9609
Adobe Acrobat Reader Continuous vulnerability analysis and mitigation

Overview

Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier contain an out-of-bounds read vulnerability (CVE-2020-9609) discovered by Aleksandar Nikolic of Cisco Talos. The vulnerability was disclosed to Adobe on March 24, 2020, and was publicly released on May 12, 2020 (Talos Report, Adobe Advisory).

Technical details

The vulnerability exists in Adobe Acrobat Reader DC's JavaScript handling of the submitForm function. When processing unicode strings during this function call, the application fails to properly terminate strings when converting between different types. This results in reading out of bounds memory, as the string termination check looks for double NULL bytes that may not exist. The vulnerability received a CVSS v3.1 Base Score of 5.5 (Medium) with vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N (NVD, Talos Report).

Impact

Successful exploitation of this vulnerability could lead to information disclosure and potential memory corruption. The out-of-bounds read can be leveraged to leak sensitive memory contents, which could be used to bypass security mitigations such as ASLR. Additionally, the incorrect string length calculation could potentially be abused to cause adjacent heap memory overwrites (Talos Report).

Exploitability

The vulnerability requires user interaction to be exploited, as the victim needs to open a malicious PDF file or access a malicious web page. While the submitForm function has some restrictions on when it can be executed (primarily in browser context), the vulnerable code path is always triggered when processing specific JavaScript code (Talos Report).

Mitigation and workarounds

Adobe has released security updates to address this vulnerability. Users should update to the latest versions of Adobe Acrobat and Reader. For Acrobat and Reader DC Continuous track, update to version 2020.006.20042 or later. For Classic 2017 track, update to version 2017.011.30166 or later. For Classic 2015 track, update to version 2015.006.30518 or later (Adobe Advisory).

Additional resources


SourceThis report was generated using AI

Related Adobe Acrobat Reader Continuous vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48373HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
NoYesJul 17, 2026
CVE-2020-9695HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
NoYesJun 23, 2026
CVE-2026-47965HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader_dc
NoYesJun 12, 2026
CVE-2020-9713MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader
NoYesJun 23, 2026
CVE-2020-9711MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:*
NoYesJun 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management