
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-9711 is an out-of-bounds read vulnerability in Adobe Acrobat Reader that can lead to disclosure of sensitive memory contents. It affects Acrobat Reader and Acrobat DC versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523, and earlier across both Windows and macOS platforms. The vulnerability was disclosed by Adobe and carries a CVSS v3.1 base score of 5.5 (Medium) (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-125 (Out-of-bounds Read), where the application reads data beyond the intended buffer boundary during PDF file processing. An attacker crafts a malicious PDF file that, when opened by a victim, triggers the out-of-bounds read and causes the application to expose sensitive memory contents. Exploitation requires local access in the sense that the victim must open a specially crafted file, but no privileges are required on the part of the attacker. No public proof-of-concept code has been identified (Adobe Advisory, GitHub Advisory).
Successful exploitation results in disclosure of sensitive memory contents from the affected Acrobat Reader or Acrobat DC process, posing a high confidentiality risk. There is no impact to integrity or availability. The leaked memory could potentially contain sensitive data such as credentials, encryption keys, or other in-memory information, and could theoretically be used to aid further exploitation such as bypassing ASLR (Adobe Advisory, GitHub Advisory).
Adobe addressed this vulnerability in the APSB20-48 security update. Users should update to Acrobat DC (Continuous) version 2020.012.20041 or later, Acrobat 2017 (Classic) version 2017.011.30175 or later, and Acrobat 2015 (Classic) version 2015.006.30527 or later. As a general precaution, users should avoid opening PDF files from untrusted or unknown sources, and organizations may consider implementing application whitelisting or restricting Adobe Reader usage in high-risk environments (Adobe Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."