KLA11393
Multiple vulnerabilities in Adobe Acrobat and Acrobat Reader

Updated: 06/03/2020
Detect date
?
01/03/2019
Severity
?
Critical
Description

Multiple serious vulnerabilities were found in Adobe Acrobat and Acrobat Reader. Malicious users can exploit these vulnerabilities to execute arbitrary code, gain privileges.

Below is a complete list of vulnerabilities:

  1. An use-after-free vulnerability can be exploited remotely to execute arbitrary code;
  2. A security bypass vulnerability can be exploited remotely to gain privileges;
  3. An type confusion vulnerability can be exploited remotely to execute arbitrary code.
Affected products

Adobe Acrobat DC Continuous earlier than 2019.010.20069
Adobe Acrobat Reader DC Continuous earlier than 2019.010.20069
Adobe Acrobat 2017 (Classic 2017 Track) earlier than 2017.011.30113
Adobe Acrobat Reader 2017 (Classic 2017 Track) earlier than 2017.011.30113
Adobe Acrobat DC (Classic 2015 Track) earlier than 2015.006.30464
Adobe Acrobat Reader DC (Classic 2015 Track) earlier than 2015.006.30464

Solution

Update to the latest version
Download Adobe Acrobat Reader DC

Original advisories

APSB19-02

Impacts
?
ACE 
[?]

PE 
[?]
Related products
Adobe Acrobat Reader DC Continuous
Adobe Acrobat Reader DC Classic
Adobe Acrobat DC Continuous
Adobe Acrobat DC Classic
Adobe Acrobat Reader 2017
Adobe Acrobat 2017
CVE-IDS
?
CVE-2018-160189.3Critical
CVE-2018-160119.3Critical
CVE-2019-71317.5Critical
Find out the statistics of the vulnerabilities spreading in your region