KLA11708
Multiple vulnerabilities in Adobe Acrobat and Adobe Acrobat Reader
Обновлено: 22/05/2020
Дата обнаружения
17/03/2020
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Adobe Acrobat and Adobe Acrobat Reader. Malicious users can exploit these vulnerabilities to obtain sensitive information, execute arbitrary code, gain privileges.

Below is a complete list of vulnerabilities:

  1. Memory address leak vulnerability can be exploited to obtain sensitive information.
  2. Out of bounds read  vulnerability can be exploited to obtain sensitive information.
  3. Out of bounds write vulnerability can be exploited to execute arbitrary code.
  4. Use after free vulnerability can be exploited to execute arbitrary code.
  5. Buffer overflow vulnerability can be exploited to execute arbitrary code.
  6. Memory corruption vulnerability can be exploited to execute arbitrary code.
  7. Insecure library loading (DLL hijacking) vulnerability can be exploited to gain privileges.
  8. Stack-based buffer overflow vulnerability can be exploited to execute arbitrary code.
Пораженные продукты

Acrobat DC Continuous earlier than 2020.006.20042
Acrobat Reader DC Continuous earlier than 2020.006.20042
Acrobat 2017 Classic 2017 earlier than 2017.011.30166
Acrobat Reader 2017 Classic 2017 earlier than 2017.011.30166
Acrobat 2015 Classic 2015 earlier than 2015.006.30518
Acrobat Reader 2015 Classic 2015 earlier than 2015.006.30518

Решение

Update to the latest version
Download Adobe Acrobat Reader DC

Первичный источник обнаружения
APSB20-13
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

PE 
[?]
Связанные продукты
Adobe Acrobat Reader DC Continuous
Adobe Acrobat Reader DC Classic
Adobe Acrobat DC Continuous
Adobe Acrobat DC Classic
Adobe Acrobat Reader 2017
Adobe Acrobat 2017
CVE-IDS
CVE-2020-38000.0Unknown
CVE-2020-38040.0Unknown
CVE-2020-37950.0Unknown
CVE-2020-37930.0Unknown
CVE-2020-37920.0Unknown
CVE-2020-38050.0Unknown
CVE-2020-38070.0Unknown
CVE-2020-38010.0Unknown
CVE-2020-37970.0Unknown
CVE-2020-38020.0Unknown
CVE-2020-38030.0Unknown
CVE-2020-37990.0Unknown
CVE-2020-38060.0Unknown