Summary
Adobe Acrobat and Reader contain a use-after-free in PDF ESObject handling. A malicious PDF with embedded JavaScript can trigger stale object reuse, leading to memory corruption, heap spraying, and an eventual arbitrary code execution primitive. The flaw does not require authentication, but the victim must open the crafted document.
Why Planned Fix?
4/6Exploitation Details
Execute arbitrary code as the current user
RCE (Remote Code Execution)Affected Software
| Product | Affected Versions |
|---|---|
| Adobe Acrobat | 2020.009.20074 and earlier; 2020.001.30002; 2017.011.30171 and earlier; 2015.006.30523 and earlier |
| Adobe Acrobat Reader | 2020.009.20074 and earlier; 2020.001.30002; 2017.011.30171 and earlier; 2015.006.30523 and earlier |
Desktop software for viewing, creating, signing, and editing PDF documents.
Affected ComponentPDF JavaScript ESObject/data-object handling in the Acrobat/Reader ESObjects cache.
PDF JavaScript ESObject/data-object handling in the Acrobat/Reader ESObjects cache.
Not available
Not available
Upgrade Adobe Acrobat/Reader to 2020.012.20041 (Continuous), 2020.001.30005 (Classic 2020), 2017.011.30175 (Classic 2017), or 2015.006.30527 (Classic 2015), or later.
Upgrade Adobe Acrobat/Reader to 2020.012.20041 (Continuous), 2020.001.30005 (Classic 2020), 2017.011.30175 (Classic 2017), or 2015.006.30527 (Classic 2015), or later.
Probability of exploitation in the next 30 days
Worse than 98% of all CVEs
No known threat actors
No detection rules available
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Affected Software (CPE) (6)
- •cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:*
- •cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
- •cpe:2.3:a:adobe:acrobat_dc:20.001.30002:*:*:*:classic:*:*:*
- •cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:*
- •cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
- •cpe:2.3:a:adobe:acrobat_reader_dc:20.001.30002:*:*:*:classic:*:*:*
Sources
| Source | Article |
|---|---|
| nvd.nist.gov | CVE-2020-9715 Detail |
| helpx.adobe.com | Adobe Security Bulletin APSB20-48 |
| thezdi.com | Exploiting a Use-After-Free in Adobe Reader |
| asec.ahnlab.com | APT Attacks Using PDF Files, Possibly by North Korea Related Group |
| rapid7.com | Adobe Acrobat: CVE-2020-9715 |
| cisa.gov | Known Exploited Vulnerabilities Catalog |
| github.com | lsw29475/CVE-2020-9715 |
| github.com | wonjunchun/CVE-2020-9715 |
Priority History
Initial analysis