First published: Thu Jun 25 2020(Updated: )
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an invalid memory access vulnerability. Successful exploitation could lead to information disclosure.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | >=15.006.30060<15.006.30518 | |
Adobe Acrobat Reader | >=15.008.20082<20.006.20042 | |
Adobe Acrobat Reader | >=17.011.30059<17.011.30166 | |
Adobe Acrobat Reader Notification Manager | >=15.006.30060<15.006.30518 | |
Adobe Acrobat Reader Notification Manager | >=15.008.20082<20.006.20042 | |
Adobe Acrobat Reader Notification Manager | >=17.011.30059<17.011.30166 | |
Apple iOS and macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9595 is classified as a critical vulnerability due to its potential for information disclosure.
To mitigate CVE-2020-9595, users should update Adobe Acrobat and Reader to the latest versions provided by Adobe.
Versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, as well as 2015.006.30518 and earlier are affected by CVE-2020-9595.
CVE-2020-9595 may allow an attacker to exploit an invalid memory access vulnerability leading to information disclosure.
Yes, CVE-2020-9595 is exploitable in various editions of Adobe Acrobat DC as per the affected versions.