KLA11708
Multiple vulnerabilities in Adobe Acrobat and Adobe Acrobat Reader

Updated: 06/03/2020
Detect date
?
03/17/2020
Severity
?
Critical
Description

Multiple vulnerabilities were found in Adobe Acrobat and Adobe Acrobat Reader. Malicious users can exploit these vulnerabilities to obtain sensitive information, execute arbitrary code, gain privileges.

Below is a complete list of vulnerabilities:

  1. Memory address leak vulnerability can be exploited to obtain sensitive information.
  2. Out of bounds read  vulnerability can be exploited to obtain sensitive information.
  3. Out of bounds write vulnerability can be exploited to execute arbitrary code.
  4. Use after free vulnerability can be exploited to execute arbitrary code.
  5. Buffer overflow vulnerability can be exploited to execute arbitrary code.
  6. Memory corruption vulnerability can be exploited to execute arbitrary code.
  7. Insecure library loading (DLL hijacking) vulnerability can be exploited to gain privileges.
  8. Stack-based buffer overflow vulnerability can be exploited to execute arbitrary code.
Affected products

Acrobat DC Continuous earlier than 2020.006.20042
Acrobat Reader DC Continuous earlier than 2020.006.20042
Acrobat 2017 Classic 2017 earlier than 2017.011.30166
Acrobat Reader 2017 Classic 2017 earlier than 2017.011.30166
Acrobat 2015 Classic 2015 earlier than 2015.006.30518
Acrobat Reader 2015 Classic 2015 earlier than 2015.006.30518

Solution

Update to the latest version
Download Adobe Acrobat Reader DC

Original advisories

APSB20-13

Impacts
?
ACE 
[?]

OSI 
[?]

PE 
[?]
Related products
Adobe Acrobat Reader DC Continuous
Adobe Acrobat Reader DC Classic
Adobe Acrobat DC Continuous
Adobe Acrobat DC Classic
Adobe Acrobat Reader 2017
Adobe Acrobat 2017
CVE-IDS
?
CVE-2020-38005.0Critical
CVE-2020-38045.0Critical
CVE-2020-37957.5Critical
CVE-2020-37937.5Critical
CVE-2020-37927.5Critical
CVE-2020-380510.0Critical
CVE-2020-38077.5Critical
CVE-2020-38017.5Critical
CVE-2020-37977.5Critical
CVE-2020-38026.8High
CVE-2020-38034.4Warning
CVE-2020-37997.5Critical
CVE-2020-38065.0Critical
Find out the statistics of the vulnerabilities spreading in your region