CVE-2020-9715
9.5 CISA KEVAdobe · Acrobat and Reader
A use-after-free vulnerability in the EScript.api module of Adobe Acrobat and Reader allows an attacker to achieve arbitrary code execution by enticing a user to open a crafted PDF file.
Executive summary
Adobe Acrobat and Reader are vulnerable to a critical use-after-free flaw that is currently being actively exploited in the wild to achieve arbitrary code execution.
Vulnerability
This is a use-after-free vulnerability located within the data ESObject cache of the EScript.api module. Successful exploitation allows an unauthenticated attacker to execute arbitrary code on the host system when a victim opens a maliciously crafted PDF document.
Business impact
The CVSS score of 9.5 indicates a critical risk to organizational security, as arbitrary code execution typically leads to full system compromise. If exploited, an attacker could gain persistent access to sensitive data, deploy malware, or move laterally through the internal network. The inclusion of this vulnerability in the CISA Known Exploited Vulnerabilities catalog underscores the high probability of targeted attacks against organizations using these products.
Remediation
Immediate Action: Update Adobe Acrobat DC and Reader DC (Continuous) to version 2020.012.20041 or later, Acrobat 2020 (Classic) to 2020.001.30005 or later, Acrobat 2017 (Classic) to 2017.011.30175 or later, and Acrobat 2015 (Classic) to 2015.006.30527 or later.
Proactive Monitoring: Monitor endpoint logs for suspicious child processes spawned by Acrobat or Reader, particularly those involving PowerShell, cmd.exe, or unusual network connections initiated from the application.
Compensating Controls: Implement browser and email security policies that restrict the automatic opening of PDF files and utilize endpoint detection and response tools to block execution of non-standard file types or unexpected binary behavior originating from Adobe processes.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as evidenced by available GitHub repositories.
Analyst recommendation
Given the critical severity of this vulnerability and the confirmed reports of active exploitation, immediate patching is required across all enterprise environments. Security teams should prioritize this update as a top-tier incident response task to prevent potential data breaches or system takeovers.