Junglewise Threat Intelligence

CVE-2020-9713: Adobe Acrobat and Reader out-of-bounds read

CVE-2020-9713 · Severity: medium · CVSS 5.5 · Published 2026-06-23

Technologies: Adobe Acrobat Reader. Vendors: Adobe.

Executive brief

Adobe Acrobat and Reader are widely used applications for viewing and managing PDF documents. A security flaw in these programs could allow an attacker to access sensitive information stored in the computer's memory if a user is tricked into opening a specially crafted malicious file. This could lead to the exposure of private data or help an attacker bypass other security protections on the system.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in multiple versions of Adobe Acrobat and Reader. The flaw occurs when the application reads data past the end of the intended buffer while processing a PDF file. An attacker can exploit this by convincing a user to open a specifically crafted malicious document. Successful exploitation allows the attacker to read sensitive information from the process memory, which could potentially be used to bypass security mitigations like ASLR. The vulnerability is addressed in Adobe security bulletin APSB20-48.

Affected products

  • Adobe Acrobat Reader 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, 2015.006.30523 and earlier

Timeline

  • 2026-06-23: advisory: NVD publication date

References

Related threats