CVE-2020-9702 is a stack exhaustion vulnerability affecting Adobe Acrobat and Reader across multiple versions, including 2020.009.20074 and earlier. Successful exploitation, which requires user interaction (e.g., opening a malicious file), can lead to a denial-of-service condition for the application. While rated Medium severity with a CVSS score of 5.5, there is no evidence of active exploitation, public exploit code, or significant community discussion, despite some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.006.30060, <= 15.006.30523CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 15.008.20082, <= 20.009.20074CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 17.011.30059, <= 17.011.30171CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
20.001.30002CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:20.001.30002:*:*:*:classic:*:*:* | ||
>= 15.006.30060, <= 15.006.30523CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.