CVE-2020-9713
Adobe Acrobat Reader Continuous vulnerability analysis and mitigation

Overview

CVE-2020-9713 is an out-of-bounds read vulnerability (CWE-125) in Adobe Acrobat and Reader that can lead to disclosure of sensitive memory contents. It affects Adobe Acrobat DC and Reader DC (Continuous track) versions 2020.009.20074 and earlier, Classic 2020 version 2020.001.30002, Classic 2017 versions 2017.011.30171 and earlier, and Classic 2015 versions 2015.006.30523 and earlier, on both Windows and macOS. Exploitation requires a victim to open a malicious file, making user interaction a prerequisite. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (Adobe Advisory, Github Advisory).

Technical details

The vulnerability is classified as CWE-125 (Out-of-bounds Read), occurring when Adobe Acrobat or Reader processes a specially crafted PDF or compatible file and reads memory beyond the bounds of an allocated buffer. This memory disclosure can expose sensitive data from the application's memory space to an attacker. The attack vector is local, requiring no privileges, but does require user interaction — specifically, a victim must open a malicious file delivered via phishing, email attachment, or other social engineering means. No public proof-of-concept or detailed technical write-up has been identified (Adobe Advisory, Github Advisory).

Impact

Successful exploitation results in a high confidentiality impact, as sensitive memory contents from the Adobe Acrobat/Reader process can be disclosed to the attacker. There is no impact on integrity or availability. The scope is unchanged, meaning the vulnerability is confined to the affected application's security context and does not directly enable lateral movement or privilege escalation on its own. However, leaked memory data could potentially be leveraged to bypass ASLR or aid in chaining with other vulnerabilities (Adobe Advisory).

Mitigation and workarounds

Adobe addressed this vulnerability in security bulletin APSB20-48. Users should update to the following fixed versions or later: Acrobat DC / Reader DC (Continuous) version 2020.012.20041 or later, Acrobat 2020 / Reader 2020 (Classic) version 2020.001.30005 or later, Acrobat 2017 / Reader 2017 (Classic) version 2017.011.30175 or later, and Acrobat 2015 / Reader 2015 (Classic) version 2015.006.30527 or later. As a general precaution, users should avoid opening PDF files from untrusted or unknown sources, and organizations should consider enabling Adobe's Protected View or sandboxing features (Adobe Advisory).

Additional resources


SourceThis report was generated using AI

Related Adobe Acrobat Reader Continuous vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-9695HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026
CVE-2026-47965HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat
NoYesJun 12, 2026
CVE-2026-47955HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
NoYesJun 09, 2026
CVE-2020-9713MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026
CVE-2020-9711MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management