PT-2018-11383 · Adobe · Acrobat+1

Publicado

2018-07-10

·

Atualizado

2020-08-24

·

CVE-2018-12788

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Acrobat and Reader versions 2018.011.20040 and earlier Adobe Acrobat and Reader versions 2017.011.30080 and earlier Adobe Acrobat and Reader versions 2015.006.30418 and earlier
Description A heap overflow issue allows attackers to execute arbitrary code in the context of the current user. Successful exploitation could lead to arbitrary code execution. The vulnerability is related to the EMF and EMR ALPHABLEND image conversion functionality.
Recommendations For Adobe Acrobat and Reader versions 2018.011.20040 and earlier, update to a version later than 2018.011.20040 to resolve the issue. For Adobe Acrobat and Reader versions 2017.011.30080 and earlier, update to a version later than 2017.011.30080 to resolve the issue. For Adobe Acrobat and Reader versions 2015.006.30418 and earlier, update to a version later than 2015.006.30418 to resolve the issue. As a temporary workaround, consider disabling the image conversion functionality related to EMF and EMR ALPHABLEND until a patch is available.

Correção

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-12788
ZDI-18-680

Produtos afetados

Acrobat
Reader