Use-After-Free Vulnerability in Adobe Acrobat and Reader
CVE-2020-9722
7.8HIGH
Summary
Adobe Acrobat and Reader contain a use-after-free vulnerability that can allow an attacker to execute arbitrary code on the affected system. This vulnerability arises from improper handling of object references, which can be exploited through maliciously crafted PDF files. By successfully triggering this vulnerability, attackers may gain control over the affected system and execute unauthorized actions, potentially compromising sensitive information and system integrity.
Affected Version(s)
Adobe Acrobat and Reader 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier versions
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved