
Proof-of-concept for CVE-2020-9715, a use-after-free in Adobe Acrobat Reader DC's EScript engine. Generates a PDF that triggers the vulnerability pattern for EDR detection validation. No weaponized payload included.
Use-after-free in Adobe Acrobat Reader DC's EScript.api ESObject cache. For authorized red team EDR testing only.
Adobe Acrobat Reader DC <= 2020.009.20063. The EScript engine caches data ESObjects with keys that preserve the original encoding (ANSI or Unicode). Deletion always constructs Unicode keys, so ANSI-named entries are never purged from the cache. After GC frees the underlying object, the stale cache entry becomes a dangling pointer.
OpenAction accesses dataObjects to populate the ESObject cacheArrayBuffer allocations to reclaim the freed memoryThis PoC triggers the vulnerability pattern but does not include a weaponized payload (no shellcode, no ROP chain). It is designed to validate whether your EDR detects the exploitation technique.
python generate_poc.py # Generates CVE-2020-9715.pdf
python generate_poc.py -o custom.pdf # Custom output path
No external dependencies -- uses only Python standard library.
Your EDR should key on one or more of:
ArrayBuffer mass allocation)dataObjects access followed by forced GC and re-access (UAF pattern)OpenAction + EmbeddedFiles + JavaScriptPatched in APSB20-48 (August 2020).