Executive brief
Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A security flaw in several versions of the software could allow an attacker to access sensitive information stored in the computer's memory. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file, potentially leading to the theft of private data.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Adobe Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier. The flaw occurs when the application reads data past the end of the intended buffer while processing a file. An attacker can exploit this by convincing a user to open a specifically crafted malicious document. Successful exploitation allows for the disclosure of sensitive information from the process memory, which could be used to bypass security mitigations like ASLR. Adobe has addressed this in security bulletin APSB20-48.
Affected products
- Adobe Acrobat Reader 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier
Timeline
- 2026-06-23: disclosed: CVE published by Adobe and NVD