
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-9695 is an out-of-bounds write vulnerability in Adobe Acrobat Reader and Acrobat DC that could result in arbitrary code execution in the context of the current user. Affected versions include Acrobat Reader/Acrobat DC 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523, and earlier, across both Continuous and Classic tracks on Windows and macOS. The vulnerability was assigned by Adobe Systems Incorporated and carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, Github Advisory).
The vulnerability is classified as CWE-787 (Out-of-bounds Write), meaning the application writes data beyond the boundaries of an allocated buffer during PDF file processing. Exploitation requires a local attack vector — an attacker must deliver a specially crafted malicious PDF file and convince a victim to open it, making user interaction a required precondition. No privileges are required on the part of the attacker beyond the ability to deliver the malicious file. No public proof-of-concept exploit code has been identified (Adobe Advisory, Github Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the security context of the current user, resulting in high impact to confidentiality, integrity, and availability of the affected system. An attacker who achieves code execution could access sensitive user data, modify files, install malware, or use the compromised session as a foothold for further lateral movement within a network. The scope is limited to the current user's privileges unless combined with a privilege escalation technique (Adobe Advisory, Github Advisory).
Adobe has released patches addressing this vulnerability; users should update to versions newer than 2020.009.20074 (Continuous track), 2020.001.30002 (Classic 2020), 2017.011.30171 (Classic 2017), or 2015.006.30523 (Classic 2015). Organizations should implement user awareness training to discourage opening PDF files from untrusted or unknown sources. As an additional defense-in-depth measure, consider enabling Adobe Reader's Protected Mode (sandboxing) and restricting PDF execution in high-risk environments (Adobe Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."