CVE-2020-9715
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Adobe Acrobat Use-After-Free Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 48% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-416
מוצרים מושפעים
adobe: acrobat dc; adobe: acrobat reader dc; apple: macos; microsoft: windows
קישורים
- https://helpx.adobe.com/security/products/acrobat/apsb20-48.html Vendor Advisory
- https://helpx.adobe.com/security/products/acrobat/apsb20-48.html Vendor Advisory
- https://blog.exodusintel.com/2021/04/20/analysis-of-a-use-after-free-vulnerabi… ExploitPatchThird Party Advisory
- https://blog.exodusintel.com/2021/04/20/analysis-of-a-use-after-free-vulnerabi… ExploitPatchThird Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-991/ Third Party AdvisoryVDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-20-991/ Third Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource