KLA11674
Multiple vulnerabilities in Adobe Acrobat
Updated: 02/13/2020
Detect date
?
02/11/2020
Severity
?
Critical
Description

Multiple vulnerabilities were found in Adobe Acrobat. Malicious users can exploit these vulnerabilities to execute arbitrary code, gain privileges, cause denial of service, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. Heap overflow vulnerability can be exploited to execute arbitrary code.
  2. Use after free vulnerability can be exploited to execute arbitrary code.
  3. Privilege escalation vulnerability can be exploited to arbitrary file system write.
  4. Buffer vulnerability can be exploited to execute arbitrary code.
  5. Stack exhaustion vulnerability can be exploited to cause denial of service.
  6. Read-operation memory vulnerability can be exploited to obtain sensitive information.
Affected products

Acrobat DC Continuous earlier than 2020.006.20034
Acrobat Reader DC Continuous earlier than 2020.006.20034
Acrobat 2017 Classic 2017 earlier than 2017.011.30158
Acrobat Reader 2017 Classic 2017 earlier than 2017.011.30158
Acrobat 2015 Classic 2015 earlier than 2015.006.30510
Acrobat Reader 2015 Classic 2015 earlier than 2015.006.30510

Solution

Update to the latest version
Download Adobe Acrobat Reader DC

Original advisories

APSB20-05

Impacts
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

PE 
[?]
Related products
Adobe Acrobat
Adobe Acrobat Reader DC Continuous
Adobe Acrobat Reader DC Classic
Adobe Acrobat DC Continuous
Adobe Acrobat DC Classic
Adobe Acrobat Reader 2017
Adobe Acrobat 2017
Adobe Acrobat Reader
CVE-IDS
?
CVE-2020-37420.0Unknown
CVE-2020-37480.0Unknown
CVE-2020-37620.0Unknown
CVE-2020-37510.0Unknown
CVE-2020-37500.0Unknown
CVE-2020-37540.0Unknown
CVE-2020-37490.0Unknown
CVE-2020-37560.0Unknown
CVE-2020-37520.0Unknown
CVE-2020-37460.0Unknown
CVE-2020-37440.0Unknown
CVE-2020-37450.0Unknown
CVE-2020-37530.0Unknown
CVE-2020-37630.0Unknown
CVE-2020-37550.0Unknown
CVE-2020-37470.0Unknown
CVE-2020-37430.0Unknown