CVE-2019-8024
published 2019-08-20CVE-2019-8024: Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier…
PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
15.12%
96.3th percentile
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat_dc | >= 15.006.30060 < 15.006.30499 | 15.006.30499 |
| adobe | acrobat_dc | >= 15.008.20082 < 19.012.20036 | 19.012.20036 |
| adobe | acrobat_dc | >= 17.011.30059 < 17.011.30144 | 17.011.30144 |
| adobe | acrobat_reader_dc | >= 15.006.30060 < 15.006.30499 | 15.006.30499 |
| adobe | acrobat_reader_dc | >= 15.008.20082 < 19.012.20036 | 19.012.20036 |
| adobe | acrobat_reader_dc | >= 17.011.30059 < 17.011.30144 | 17.011.30144 |
| adobe | adobe_acrobat_and_reader | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Crash triggered immediately upon opening a malformed PDF containing a JP2 image stream with 2 mutated bytes; monitor AcroRd32.exe for access violations (code c0000005) originating from AcroRd32!AX_PDXlateToHostEx or JP2KLib!JP2KTileGeometryRegionIsTile during PDF open events. ↗
- →For poc1.pdf, the malicious mutations are at byte offsets 0x290a and 0x298b inside binary JP2 image streams; for poc2.pdf at offsets 0x5b4 and 0x62a. Scan suspicious PDFs for JP2 streams with anomalous bytes at these relative offsets. ↗
- →Without PageHeap the crash manifests in ntdll!RtlReportCriticalFailure; detection on production systems should look for AcroRd32.exe crashing with an unhandled exception referencing ntdll!RtlReportCriticalFailure shortly after PDF open. ↗
- →The freed object is released via JP2KLib!JP2KTileGeometryRegionIsTile and then accessed in AcroRd32!AX_PDXlateToHostEx; EDR/crash telemetry showing this call chain in AcroRd32.exe is a strong indicator of CVE-2019-8024 exploitation. ↗
- ·Crash reproduces most cleanly with Light PageHeap enabled in Application Verifier for AcroRd32.exe; without PageHeap the crash location differs (ntdll!RtlReportCriticalFailure), so detection signatures based on crash address may vary by environment. ↗
- ·Affected versions span multiple Adobe Acrobat/Reader tracks (2015, 2017, 2019 Classic and Continuous); ensure version-based detections cover all listed tracks up to and including 2019.012.20035, 2017.011.30143, and 2015.006.30498. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Adobe Acrobat Reader DC for Windows - Use-After-Free due to Malformed JP2 Stream
exploitdb·2019-08-15
CVE-2019-8024 Adobe Acrobat Reader DC for Windows - Use-After-Free due to Malformed JP2 Stream
Adobe Acrobat Reader DC for Windows - Use-After-Free due to Malformed JP2 Stream
---
We have observed the following access violation exception in the latest version of Adobe Acrobat Reader DC for Windows, when opening a malformed PDF file:
--- cut ---
(2040.5034): Access violation - code c0000005 (first chance)
First chance exceptions are reported before any exception handling.
This exception may be expected and handled.
eax=14080e48 ebx=00000000 ecx=148d9d48 edx=00000000 esi=0ec19d20 edi=f0f0f0f0
eip=0f29f04f esp=050faa10 ebp=050faa34 iopl=0 nv up ei ng nz na pe nc
cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00210286
AcroRd32!AX_PDXlateToHostEx+0x340fff:
0f29f04f 8b4754 mov eax,dword ptr [edi+54h] ds:002b:f0f0f144=????????
0:000> kb
# ChildEBP RetAddr Args to Child
WARNING: St
Exploit-DB
OpenSource ERP 6.3.1. - SQL Injection
exploitdb·2019-01-10·CVSS 9.8
CVE-2019-5893 [CRITICAL] OpenSource ERP 6.3.1. - SQL Injection
OpenSource ERP 6.3.1. - SQL Injection
---
#Exploit Title: OpenSource ERP SQL Injection
#Date: 10.01.2019
#Exploit Author: Emre ÖVÜNÇ
#Vendor Homepage: http://www.nelson-it.ch
#Software Link: http://sourceforge.net/projects/opensourceerp/files/Windows/erp_6.3.1.exe/download
#Version: v6.3.1
#Tested on: Windows
# CVE-2019-5893
https://github.com/EmreOvunc/OpenSource-ERP-SQL-Injection
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5893
https://www.emreovunc.com/blog/en/OpenERP-SQL-DBversion.png
# PoC
POST /db/utils/query/data.xml HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36
(KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36
Accept: */*
Content-Type: application/x-www-form-urlencoded;charset=UTF-8
Origin: http://172.16.118.142:8024
Referer: http:
Zscaler
Zscaler found Adobe Security Vulnerabilities | 08-14-2019
blogs_zscaler
Zscaler found Adobe Security Vulnerabilities | 08-14-2019
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
CVE-2016-10750 hazelcast: java deserialization in join cluster procedure leading to remote code execution
bugzilla·2019-05-23·CVSS 8.1
CVE-2016-10750 [HIGH] CVE-2016-10750 hazelcast: java deserialization in join cluster procedure leading to remote code execution
CVE-2016-10750 hazelcast: java deserialization in join cluster procedure leading to remote code execution
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization.
Upstream issue:
https://github.com/hazelcast/hazelcast/issues/8024
Upstream pull:
https://github.com/hazelcast/hazelcast/pull/12230
Discussion:
Created hazelcast tracking bugs for this issue:
Affects: fedora-all [bug 1713216]
---
This issue has been addressed in the following products:
Red Hat Fuse 7.4.0
Via RHSA-2019:2413 https://access.redhat.com/errata/RHSA-2019:2413
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2016-10750
---
Statement:
The module
2019-08-20
Published