CVE-2019-8195
published 2019-10-17CVE-2019-8195: Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and…
PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
22.89%
97.5th percentile
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat_dc | >= 15.006.30060 < 15.006.30504 | 15.006.30504 |
| adobe | acrobat_dc | >= 15.008.20082 < 19.021.20047 | 19.021.20047 |
| adobe | acrobat_dc | >= 17.011.30059 < 17.011.30150 | 17.011.30150 |
| adobe | acrobat_reader_dc | >= 15.006.30060 < 15.006.30504 | 15.006.30504 |
| adobe | acrobat_reader_dc | >= 15.008.20082 < 19.021.20047 | 19.021.20047 |
| adobe | acrobat_reader_dc | >= 17.011.30059 < 17.011.30150 | 17.011.30150 |
| adobe | adobe_acrobat_and_reader | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Crash is triggered by opening a malformed PDF containing a JBIG2Globals stream with a single byte modified at offset 0x2f5 (changed from 0x00 to 0x35); monitor for PDF files with anomalous JBIG2Globals objects. ↗
- →Exploitation results in an access violation at AcroRd32!CTJPEGTiledContentWriter::operator= due to dereferencing an uninitialized heap pointer (edx=0xc0c0c0c0); look for crash telemetry or AV exceptions in AcroRd32 at this symbol. ↗
- →The crash occurs immediately after opening the PDF document; suspicious PDFs that cause AcroRd32 to crash on open should be triaged for JBIG2Globals stream manipulation. ↗
- ·Crash reproduces most consistently with PageHeap enabled; without PageHeap the uninitialized pointer value may differ from 0xc0c0c0c0, making the specific register pattern less reliable as a detection signal. ↗
- ·Affected versions include 2019.012.20040 and earlier, 2017.011.30148 and earlier, and 2015.006.30503 and earlier across both Acrobat and Reader product lines. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/155224/Adobe-Acrobat-Reader-DC-For-Windows-Malformed-JBIG2Globals-Stream-Uninitialized-Pointer.htmlhttps://helpx.adobe.com/security/products/acrobat/apsb19-49.htmlhttp://packetstormsecurity.com/files/155224/Adobe-Acrobat-Reader-DC-For-Windows-Malformed-JBIG2Globals-Stream-Uninitialized-Pointer.htmlhttps://helpx.adobe.com/security/products/acrobat/apsb19-49.html
2019-10-17
Published