CVE-2020-9707 is an out-of-bounds read vulnerability affecting Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier, impacting systems running Adobe, Apple, and Microsoft products. This vulnerability has a CVSS score of 3.3 (LOW), indicating a local attack vector with low complexity, requiring user interaction, and potentially leading to information disclosure. There is no evidence of active exploitation (KEV: No), nor is public exploit code available (Metasploit, Nuclei, ExploitDB: None). Despite limited community discussion and media coverage, Adobe has released fixes for this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.006.30060, <= 15.006.30523CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 15.008.20082, <= 20.009.20074CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 17.011.30059, <= 17.011.30171CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
20.001.30002CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:20.001.30002:*:*:*:classic:*:*:* | ||
>= 15.006.30060, <= 15.006.30523CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.