CVE-2019-7125
published 2019-05-23CVE-2019-7125: Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier…
PriorityP353high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
13.54%
96.0th percentile
Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat_dc | 15.006.30060 – 15.006.30482 | — |
| adobe | acrobat_dc | 15.008.20082 – 19.010.20098 | — |
| adobe | acrobat_dc | 17.011.30056 – 17.011.30127 | — |
| adobe | acrobat_reader_dc | 15.006.30060 – 15.006.30482 | — |
| adobe | acrobat_reader_dc | 15.008.20082 – 19.010.20098 | — |
| adobe | acrobat_reader_dc | 17.011.30059 – 17.011.30127 | — |
| adobe | adobe_acrobat_and_reader | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Reader: Out-of-bounds memory access due to incorrect integer size promotion leads to arbitrary code execution
vendor_redhat·2019-02-01·CVSS 8.8
CVE-2019-7125 [HIGH] CWE-194 Reader: Out-of-bounds memory access due to incorrect integer size promotion leads to arbitrary code execution
Reader: Out-of-bounds memory access due to incorrect integer size promotion leads to arbitrary code execution
Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
Package: flash-plugin (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-pm3f-h97g-5966: Adobe Acrobat and Reader versions 2019
ghsa_unreviewed·2022-05-24
CVE-2019-7125 [HIGH] GHSA-pm3f-h97g-5966: Adobe Acrobat and Reader versions 2019
Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Adobe Acrobat Reader remote code execution
blogs_talos·2019-04-10·CVSS 9.8
[CRITICAL] Vulnerability Spotlight: Adobe Acrobat Reader remote code execution
## Vulnerability Spotlight: Adobe Acrobat Reader remote code execution
Aleksandar Nikolic of Cisco Talos discovered these vulnerabilities.
## Executive summary
There is a remote code execution vulnerability in Adobe Acrobat Reader that could occur if a user were to open a malicious PDF on their machine using the software. Acrobat is the most widely used PDF reader on the market, making the potential target base for these bugs fairly large. The program supports embedded JavaScript code in the PDF to allow for interactive PDF forms, giving the potential attacker the ability to precisely control memory layout and creating an additional attack surface. In accordance with our coordinated disclosure policy, Cisco Talos worked with Adobe to ensure that the issue is resolved and that an update
Talos
Vulnerability Spotlight: Adobe Acrobat Reader remote code execution
blogs_talos·2019-04-10·CVSS 9.8
[CRITICAL] Vulnerability Spotlight: Adobe Acrobat Reader remote code execution
Aleksandar Nikolic of Cisco Talos discovered these vulnerabilities.
### Executive summary
There is a remote code execution vulnerability in Adobe Acrobat Reader that could occur if a user were to open a malicious PDF on their machine using the software. Acrobat is the most widely used PDF reader on the market, making the potential target base for these bugs fairly large. The program supports embedded JavaScript code in the PDF to allow for interactive PDF forms, giving the potential attacker the ability to precisely control memory layout and creating an additional attack surface.
In accordance with our coordinated disclosure policy, Cisco Talos worked with Adobe to ensure that the issue is resolved and that an update is available for affected customers.
### Vulnerability details
Adobe
Zscaler
Zscaler found Adobe Security Vulnerabilities | 04-09-2019
blogs_zscaler
Zscaler found Adobe Security Vulnerabilities | 04-09-2019
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
CVE-2019-7125 Adobe Reader: Out-of-bounds memory access due to incorrect integer size promotion leads to arbitrary code execution
bugzilla·2019-04-10·CVSS 8.8
CVE-2019-7125 [HIGH] CVE-2019-7125 Adobe Reader: Out-of-bounds memory access due to incorrect integer size promotion leads to arbitrary code execution
CVE-2019-7125 Adobe Reader: Out-of-bounds memory access due to incorrect integer size promotion leads to arbitrary code execution
A specific JavaScript code embedded in a PDF file can lead to a heap corruption when opening a PDF document in Adobe Acrobat Reader DC 2019.8.20071. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would need to open the malicious file or access a malicious web page.
External Reference:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7125
https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0774
Discussion:
Closed NOTABUG.
2019-05-23
Published