CVE-2020-9717 is an out-of-bounds read vulnerability affecting multiple versions of Adobe Acrobat and Reader on Adobe, Apple, and Microsoft platforms. This vulnerability has a CVSS score of 7.5 (High), indicating it can be exploited remotely with low complexity, potentially leading to information disclosure. While no public exploit code is available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, it has received some media coverage and community discussion. The EPSS score is low, suggesting a limited likelihood of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.006.30060, <= 15.006.30523CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 15.008.20082, <= 20.009.20074CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 17.011.30059, <= 17.011.30171CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
20.001.30002CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:20.001.30002:*:*:*:classic:*:*:* | ||
>= 15.006.30060, <= 15.006.30523CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.