Junglewise Threat Intelligence

CVE-2020-9695: Adobe Acrobat Reader out-of-bounds write

CVE-2020-9695 · Severity: high · CVSS 7.8 · Published 2026-06-23

Technologies: Adobe Acrobat Reader. Vendors: Adobe.

Executive brief

Adobe Acrobat Reader, a widely used application for viewing and managing PDF documents, is affected by a security flaw that allows for unauthorized code execution. An attacker could gain control over a user's computer if the user is tricked into opening a specially crafted, malicious PDF file. This could lead to the theft of sensitive information, system disruption, or further malware installation on the affected device.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in multiple versions of Adobe Acrobat Reader. The flaw is triggered when the application processes a specially crafted PDF file, leading to memory corruption. An attacker can exploit this by convincing a user to open a malicious document, potentially achieving arbitrary code execution within the security context of the current user. The attack vector is local with a requirement for user interaction (UI:R). Adobe has addressed this issue in security bulletin APSB20-48.

Affected products

  • Adobe Acrobat Reader 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier

Timeline

  • 2026-06-23: disclosed: NVD Published Date
  • 2026-06-23: advisory: Adobe security bulletin APSB20-48 referenced

References

Related threats