CVE-2020-9606 is a use-after-free vulnerability affecting Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier, impacting products across Adobe, Apple, and Microsoft platforms. With a CVSS score of 7.8 (High), successful exploitation could lead to arbitrary code execution, though it requires local access and low privileges, with no user interaction needed. There is no evidence of active exploitation, nor are there public exploits available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting limited public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.006.30060, < 15.006.30518CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 15.008.20082, < 20.006.20042CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 17.011.30059, < 17.011.30166CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 15.006.30060, < 15.006.30518CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* | ||
>= 15.008.20082, < 20.006.20042CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.