CVE-2020-9715
Adobe Acrobat Use-After-Free Vulnerability
- Published
- Aug 19, 2020
- Updated
- Apr 13, 2026
- Assigning CNA
- adobe
- Evidence observed
- Apr 13, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HModerate · next 30 days
- Percentile
- 98.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .
Sources
2Proof-of-concept for CVE-2020-9715, a use-after-free in Adobe Acrobat Reader DC's EScript engine. Generates a PDF that triggers the vulnerability pattern for EDR detection validation. No weaponized payload included.
Proof-of-concept exploit for CVE-2020-9715, a remote code execution vulnerability in Adobe Acrobat and Reader.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.