CVE-2020-9713: Acrobat Reader | Out-of-bounds Read (CWE-125)
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Acrobat and Readerto a version that resolves this vulnerability.Fixed in 2020.009.20074Patch 2020.009.20074 and earlier - Upgrade
Upgrade
Adobe Acrobat and Readerto a version that resolves this vulnerability.Fixed in 2020.001.30002Patch 2020.001.30002 - Upgrade
Upgrade
Adobe Acrobat and Readerto a version that resolves this vulnerability.Fixed in 2017.011.30171Patch 2017.011.30171 and earlier - Upgrade
Upgrade
Adobe Acrobat and Readerto a version that resolves this vulnerability.Fixed in 2015.006.30523Patch 2015.006.30523 and earlier - Compensating control
Since exploitation requires user interaction (victim opening a malicious file), reduce exposure by preventing users from opening untrusted/malicious PDF files (e.g., via email/content filtering and user training).
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9713?
CVE-2020-9713 has a medium severity rating of 5.5.
How do I fix CVE-2020-9713?
To fix CVE-2020-9713, users should update Adobe Acrobat and Reader to the latest versions available.
What is the impact of CVE-2020-9713?
CVE-2020-9713 can lead to the disclosure of sensitive memory information.
Which versions of Adobe Acrobat and Reader are affected by CVE-2020-9713?
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, and 2017.011.30171 and earlier are affected by CVE-2020-9713.
Can an attacker exploit CVE-2020-9713 remotely?
An attacker could exploit CVE-2020-9713 to disclose sensitive information, but exploitation may require user interaction.