CVE-2020-9695
Adobe Acrobat Reader Continuous vulnerability analysis and mitigation

Overview

CVE-2020-9695 is an out-of-bounds write vulnerability in Adobe Acrobat Reader and Acrobat DC that could result in arbitrary code execution in the context of the current user. Affected versions include Acrobat Reader/Acrobat DC 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523, and earlier, across both Continuous and Classic tracks on Windows and macOS. The vulnerability was assigned by Adobe Systems Incorporated and carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, Github Advisory).

Technical details

The vulnerability is classified as CWE-787 (Out-of-bounds Write), meaning the application writes data beyond the boundaries of an allocated buffer during PDF file processing. Exploitation requires a local attack vector — an attacker must deliver a specially crafted malicious PDF file and convince a victim to open it, making user interaction a required precondition. No privileges are required on the part of the attacker beyond the ability to deliver the malicious file. No public proof-of-concept exploit code has been identified (Adobe Advisory, Github Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary code in the security context of the current user, resulting in high impact to confidentiality, integrity, and availability of the affected system. An attacker who achieves code execution could access sensitive user data, modify files, install malware, or use the compromised session as a foothold for further lateral movement within a network. The scope is limited to the current user's privileges unless combined with a privilege escalation technique (Adobe Advisory, Github Advisory).

Mitigation and workarounds

Adobe has released patches addressing this vulnerability; users should update to versions newer than 2020.009.20074 (Continuous track), 2020.001.30002 (Classic 2020), 2017.011.30171 (Classic 2017), or 2015.006.30523 (Classic 2015). Organizations should implement user awareness training to discourage opening PDF files from untrusted or unknown sources. As an additional defense-in-depth measure, consider enabling Adobe Reader's Protected Mode (sandboxing) and restricting PDF execution in high-risk environments (Adobe Advisory).

Additional resources


SourceThis report was generated using AI

Related Adobe Acrobat Reader Continuous vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-9695HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026
CVE-2026-47965HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat
NoYesJun 12, 2026
CVE-2026-47955HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
NoYesJun 09, 2026
CVE-2020-9713MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026
CVE-2020-9711MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management