
Cloud Vulnerability DB
A community-led vulnerabilities database
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier contain an out-of-bounds read vulnerability (CVE-2020-9609) discovered by Aleksandar Nikolic of Cisco Talos. The vulnerability was disclosed to Adobe on March 24, 2020, and was publicly released on May 12, 2020 (Talos Report, Adobe Advisory).
The vulnerability exists in Adobe Acrobat Reader DC's JavaScript handling of the submitForm function. When processing unicode strings during this function call, the application fails to properly terminate strings when converting between different types. This results in reading out of bounds memory, as the string termination check looks for double NULL bytes that may not exist. The vulnerability received a CVSS v3.1 Base Score of 5.5 (Medium) with vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N (NVD, Talos Report).
Successful exploitation of this vulnerability could lead to information disclosure and potential memory corruption. The out-of-bounds read can be leveraged to leak sensitive memory contents, which could be used to bypass security mitigations such as ASLR. Additionally, the incorrect string length calculation could potentially be abused to cause adjacent heap memory overwrites (Talos Report).
The vulnerability requires user interaction to be exploited, as the victim needs to open a malicious PDF file or access a malicious web page. While the submitForm function has some restrictions on when it can be executed (primarily in browser context), the vulnerable code path is always triggered when processing specific JavaScript code (Talos Report).
Adobe has released security updates to address this vulnerability. Users should update to the latest versions of Adobe Acrobat and Reader. For Acrobat and Reader DC Continuous track, update to version 2020.006.20042 or later. For Classic 2017 track, update to version 2017.011.30166 or later. For Classic 2015 track, update to version 2015.006.30518 or later (Adobe Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."