HIGH 7.8

CVE-2020-9695: Adobe Acrobat Reader Out-of-Bounds Write RCE Vulnerability

Adobe Acrobat Reader contains a memory corruption flaw that allows attackers to execute arbitrary code on a user's system when a victim opens a specially crafted PDF file. The vulnerability affects multiple versions across Windows and macOS platforms. While the flaw is serious, it requires an attacker to socially engineer a user into opening a malicious document, making it a targeted rather than worm-like threat.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.8 HIGH · CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-787
Affected products
8 configuration(s)
Published / Modified
2026-06-23 / 2026-06-26

NVD description (verbatim)

Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2020-9695 is an out-of-bounds write vulnerability (CWE-787) in Adobe Acrobat Reader that enables arbitrary code execution with the privileges of the logged-in user. The flaw exists in Acrobat Reader 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier versions running on Windows and macOS. The out-of-bounds write condition permits an attacker to overwrite adjacent memory regions, leading to code execution in the reader's process context. Exploitation mandates user interaction—specifically, opening a malicious PDF file.

Business impact

A successful attack leveraging this vulnerability could lead to unauthorized access to sensitive documents, lateral movement within corporate networks via compromised user accounts, intellectual property theft, and potential ransomware deployment. Organizations relying on Acrobat Reader for document workflows face elevated risk, particularly if users receive external PDFs from untrusted sources. The requirement for user interaction limits blast radius but increases social engineering risk vectors.

Affected systems

Adobe Acrobat Reader DC, Adobe Acrobat DC, and related versions on both Windows and macOS platforms are vulnerable. Specific affected versions include 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and all earlier releases. Organizations using legacy Acrobat Reader versions face extended exposure.

Exploitability

Exploitation requires user interaction and local file access. An attacker must craft a malicious PDF and convince a victim to open it—typically through email, file sharing platforms, or web downloads. Once opened, the out-of-bounds write is triggered, allowing code execution. The CVSS score of 7.8 (HIGH) reflects the high impact (confidentiality, integrity, availability all affected) combined with the local attack vector and user interaction requirement. This is not a wormable vulnerability, but it is highly effective in targeted attacks against organizations handling sensitive documents.

Remediation

Adobe has released patched versions addressing this vulnerability. Verify the specific patch versions applicable to your environment against Adobe's security advisory. Users should upgrade Acrobat Reader DC and related products to the latest available version. Organizations should implement a phased rollout plan prioritizing business-critical systems and high-risk user groups.

Patch guidance

Update Adobe Acrobat Reader to a version released after the publication of this CVE. Consult Adobe's official security advisory for exact patch version numbers and supported upgrade paths for your specific Acrobat product and operating system. Test patches in a non-production environment before enterprise deployment. For users unable to patch immediately, consider disabling PDF opening in email clients and restricting file type execution policies.

Detection guidance

Monitor for suspicious PDF files in email gateways and file sharing systems. Endpoint detection and response (EDR) tools should track unusual process execution spawned from Acrobat Reader, including unexpected network connections or file system modifications. Look for crash logs and application errors in Acrobat Reader processes, which may indicate exploitation attempts. Network indicators include anomalous outbound connections from systems opening untrusted PDFs.

Why prioritize this

This vulnerability merits urgent attention due to its HIGH severity score, wide product coverage, and prevalence of Acrobat Reader in enterprise environments. Although user interaction is required, the social engineering required is straightforward—sending a malicious PDF is a common attack pattern. The vulnerability affects multiple product lines and legacy versions still in use across organizations, expanding the affected population.

Risk score, explained

The CVSS 3.1 score of 7.8 reflects high impact across all three security dimensions (confidentiality, integrity, availability compromise), a local attack vector, low attack complexity, and no privilege requirements. User interaction is required, which moderates the score slightly. The out-of-bounds write primitive is a well-understood exploitation technique with reliable code execution paths, contributing to the HIGH severity assessment.

Frequently asked questions

What versions of Acrobat Reader are affected?

Acrobat Reader 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and all earlier versions are vulnerable. Check your version in Help > About to determine if you are affected, and verify exact patched versions against Adobe's official advisory.

Can this vulnerability be exploited without user interaction?

No. The vulnerability requires a user to open a malicious PDF file. An attacker cannot trigger the flaw remotely or through passive network exposure. This requirement for user interaction is why social engineering and targeted delivery are critical to exploitation success.

Are both Windows and macOS systems at risk?

Yes, both Windows and macOS versions of Acrobat Reader are affected. However, exploit techniques and payload delivery may differ between operating systems. Ensure patches are deployed across both platforms in your environment.

Is this vulnerability currently being exploited in the wild?

As of the publication and modification dates provided, this vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning no widespread active exploitation has been officially documented. However, organizations should not assume the absence of targeted exploitation and should prioritize patching accordingly.

This analysis is provided for informational purposes to support security decision-making. SEC.co does not provide legal or compliance advice. Organizations must verify patch availability, compatibility, and deployment timelines against official Adobe security advisories and their own change management policies. The absence of a CVE from the CISA KEV catalog does not guarantee absence of exploitation. Security teams should conduct risk assessments specific to their environment, user populations, and threat model. Source: NVD (public-domain), retrieved 2026-07-28. Analysis generated by SEC.co (claude-haiku-4-5).