Executive brief
Adobe Acrobat and Reader, widely used applications for viewing and managing PDF documents, contain a critical security flaw. An attacker could exploit this vulnerability to take control of a user's computer if the user is tricked into opening a specially crafted PDF file. This vulnerability has been observed being used in active attacks in the wild.
Technical details
A use-after-free (CWE-416) vulnerability exists in Adobe Acrobat and Reader across multiple versions (Continuous and Classic tracks). The flaw is triggered when the application attempts to access memory that has already been deallocated, typically during the processing of malformed PDF content. While the attack vector is classified as local because it requires the user to open a file, it can be delivered via remote means such as email or web downloads. Successful exploitation allows an attacker to execute arbitrary code in the context of the current user. This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. Adobe has released patches to address this issue.
Affected products
- Adobe Acrobat DC 20.009.20074 and earlier, 2020.001.30002, 17.011.30171 and earlier, 15.006.30523 and earlier
- Adobe Acrobat Reader DC 20.009.20074 and earlier, 2020.001.30002, 17.011.30171 and earlier, 15.006.30523 and earlier
Timeline
- 2020-08-19: advisory: Initial NVD publication
- 2020-08-11: patched: Adobe released security bulletin APSB20-48
- 2026-04-13: kev added: CISA added to Known Exploited Vulnerabilities catalog