KLA11674
Multiple vulnerabilities in Adobe Acrobat

Обновлено: 10/03/2021
Дата обнаружения
11/02/2020
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Adobe Acrobat. Malicious users can exploit these vulnerabilities to execute arbitrary code, gain privileges, cause denial of service, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. Heap overflow vulnerability can be exploited to execute arbitrary code.
  2. Use after free vulnerability can be exploited to execute arbitrary code.
  3. Privilege escalation vulnerability can be exploited to arbitrary file system write.
  4. Buffer vulnerability can be exploited to execute arbitrary code.
  5. Stack exhaustion vulnerability can be exploited to cause denial of service.
  6. Read-operation memory vulnerability can be exploited to obtain sensitive information.
Пораженные продукты

Acrobat DC Continuous earlier than 2020.006.20034
Acrobat Reader DC Continuous earlier than 2020.006.20034
Acrobat 2017 Classic 2017 earlier than 2017.011.30158
Acrobat Reader 2017 Classic 2017 earlier than 2017.011.30158
Acrobat 2015 Classic 2015 earlier than 2015.006.30510
Acrobat Reader 2015 Classic 2015 earlier than 2015.006.30510

Решение

Update to the latest version
Download Adobe Acrobat Reader DC

Первичный источник обнаружения
APSB20-05
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

PE 
[?]
Связанные продукты
Adobe Acrobat
Adobe Acrobat Reader DC Continuous
Adobe Acrobat Reader DC Classic
Adobe Acrobat DC Continuous
Adobe Acrobat DC Classic
Adobe Acrobat Reader 2017
Adobe Acrobat 2017
Adobe Acrobat Reader
CVE-IDS
CVE-2020-37486.8High
CVE-2020-37565.0Critical
CVE-2020-37445.0Critical
CVE-2020-37535.0Critical
CVE-2020-37555.0Critical
CVE-2020-37475.0Critical
Узнай статистику распространения уязвимостей в твоем регионе