CVE-2020-9711
Adobe Acrobat Reader Continuous vulnerability analysis and mitigation

Overview

CVE-2020-9711 is an out-of-bounds read vulnerability in Adobe Acrobat Reader that can lead to disclosure of sensitive memory contents. It affects Acrobat Reader and Acrobat DC versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523, and earlier across both Windows and macOS platforms. The vulnerability was disclosed by Adobe and carries a CVSS v3.1 base score of 5.5 (Medium) (Adobe Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-125 (Out-of-bounds Read), where the application reads data beyond the intended buffer boundary during PDF file processing. An attacker crafts a malicious PDF file that, when opened by a victim, triggers the out-of-bounds read and causes the application to expose sensitive memory contents. Exploitation requires local access in the sense that the victim must open a specially crafted file, but no privileges are required on the part of the attacker. No public proof-of-concept code has been identified (Adobe Advisory, GitHub Advisory).

Impact

Successful exploitation results in disclosure of sensitive memory contents from the affected Acrobat Reader or Acrobat DC process, posing a high confidentiality risk. There is no impact to integrity or availability. The leaked memory could potentially contain sensitive data such as credentials, encryption keys, or other in-memory information, and could theoretically be used to aid further exploitation such as bypassing ASLR (Adobe Advisory, GitHub Advisory).

Mitigation and workarounds

Adobe addressed this vulnerability in the APSB20-48 security update. Users should update to Acrobat DC (Continuous) version 2020.012.20041 or later, Acrobat 2017 (Classic) version 2017.011.30175 or later, and Acrobat 2015 (Classic) version 2015.006.30527 or later. As a general precaution, users should avoid opening PDF files from untrusted or unknown sources, and organizations may consider implementing application whitelisting or restricting Adobe Reader usage in high-risk environments (Adobe Advisory).

Additional resources


SourceThis report was generated using AI

Related Adobe Acrobat Reader Continuous vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-9695HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026
CVE-2026-47965HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat
NoYesJun 12, 2026
CVE-2026-47955HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
NoYesJun 09, 2026
CVE-2020-9713MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026
CVE-2020-9711MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management