CVE-2018-19716
published 2019-01-18CVE-2018-19716: Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version…
PriorityP351critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
9.74%
95.0th percentile
Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat_dc | 15.006.30060 – 15.006.30457 | — |
| adobe | acrobat_dc | 15.006.30060 – 15.006.30456 | — |
| adobe | acrobat_dc | 15.008.20082 – 19.008.20081 | — |
| adobe | acrobat_dc | 15.008.20082 – 19.008.20080 | — |
| adobe | acrobat_dc | 17.011.30056 – 17.011.30106 | — |
| adobe | acrobat_dc | 17.011.30056 – 17.011.30105 | — |
| adobe | acrobat_reader_dc | 15.006.30060 – 15.006.30457 | — |
| adobe | acrobat_reader_dc | 15.006.30060 – 15.006.30456 | — |
| adobe | acrobat_reader_dc | 15.008.20082 – 19.008.20081 | — |
| adobe | acrobat_reader_dc | 15.008.20082 – 19.008.20080 | — |
| adobe | acrobat_reader_dc | 17.011.30059 – 17.011.30106 | — |
| adobe | acrobat_reader_dc | 17.011.30059 – 17.011.30105 | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Adobe Acrobat Reader remote code execution
blogs_talos·2019-04-10·CVSS 9.8
[CRITICAL] Vulnerability Spotlight: Adobe Acrobat Reader remote code execution
## Vulnerability Spotlight: Adobe Acrobat Reader remote code execution
Aleksandar Nikolic of Cisco Talos discovered these vulnerabilities.
## Executive summary
There is a remote code execution vulnerability in Adobe Acrobat Reader that could occur if a user were to open a malicious PDF on their machine using the software. Acrobat is the most widely used PDF reader on the market, making the potential target base for these bugs fairly large. The program supports embedded JavaScript code in the PDF to allow for interactive PDF forms, giving the potential attacker the ability to precisely control memory layout and creating an additional attack surface. In accordance with our coordinated disclosure policy, Cisco Talos worked with Adobe to ensure that the issue is resolved and that an update
Talos
Vulnerability Spotlight: Adobe Acrobat Reader remote code execution
blogs_talos·2019-04-10·CVSS 9.8
[CRITICAL] Vulnerability Spotlight: Adobe Acrobat Reader remote code execution
Aleksandar Nikolic of Cisco Talos discovered these vulnerabilities.
### Executive summary
There is a remote code execution vulnerability in Adobe Acrobat Reader that could occur if a user were to open a malicious PDF on their machine using the software. Acrobat is the most widely used PDF reader on the market, making the potential target base for these bugs fairly large. The program supports embedded JavaScript code in the PDF to allow for interactive PDF forms, giving the potential attacker the ability to precisely control memory layout and creating an additional attack surface.
In accordance with our coordinated disclosure policy, Cisco Talos worked with Adobe to ensure that the issue is resolved and that an update is available for affected customers.
### Vulnerability details
Adobe
Talos
Vulnerability Spotlight: Adobe Acrobat Reader DC text field remote code execution vulnerability
blogs_talos·2018-12-11·CVSS 9.8
[CRITICAL] Vulnerability Spotlight: Adobe Acrobat Reader DC text field remote code execution vulnerability
## Vulnerability Spotlight: Adobe Acrobat Reader DC text field remote code execution vulnerability
Aleksandar Nikolic of Cisco Talos discovered this vulnerability.
## Executive summary
Adobe Acrobat Reader DC contains a vulnerability that could allow an attacker to remotely execute code on the victim’s machine. If the attacker tricks the user into opening a specially crafted PDF with specific JavaScript, they could cause heap corruption. The user could also trigger this bug if they open a specially crafted email attachment. In accordance with our coordinated disclosure policy, Cisco Talos worked with Adobe to ensure that these issues are resolved and that an update is available for affected customers.
## Vulnerability details
Adobe Acrobat Reader DC text field value remote code execut
Talos
Vulnerability Spotlight: Adobe Acrobat Reader DC text field remote code execution vulnerability
blogs_talos·2018-12-11·CVSS 9.8
[CRITICAL] Vulnerability Spotlight: Adobe Acrobat Reader DC text field remote code execution vulnerability
Aleksandar Nikolic of Cisco Talos discovered this vulnerability.
### Executive summary
Adobe Acrobat Reader DC contains a vulnerability that could allow an attacker to remotely execute code on the victim’s machine. If the attacker tricks the user into opening a specially crafted PDF with specific JavaScript, they could cause heap corruption. The user could also trigger this bug if they open a specially crafted email attachment.
In accordance with our coordinated disclosure policy, Cisco Talos worked with Adobe to ensure that these issues are resolved and that an update is available for affected customers.
### Vulnerability details
Adobe Acrobat Reader DC text field value remote code execution vulnerability (TALOS-2018-0704/CVE-2018-19716)
Adobe Acrobat Reader supports embedded JavaSc
2019-01-18
Published