PT-2018-13354 · Adobe · Reader Dc+2
Publicado
2018-12-17
·
Atualizado
2019-10-03
·
CVE-2018-16018
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Acrobat and Reader versions 2019.010.20064 and earlier
Adobe Acrobat and Reader versions 2017.011.30110 and earlier
Adobe Acrobat and Reader versions 2015.006.30461 and earlier
Description
A security bypass issue exists, potentially allowing attackers to escalate privileges. The vulnerability is related to the Adobe Reader DC JavaScript API, with specific issues in
ANSendForSharedReview, AnnotsString object, read-only variables, CBSharedReviewCompleteAutomation, and ANSendForFormDistribution JavaScript API restrictions bypass.Recommendations
For versions 2019.010.20064 and earlier, update to a version later than 2019.010.20064 to resolve the issue.
For versions 2017.011.30110 and earlier, update to a version later than 2017.011.30110 to resolve the issue.
For versions 2015.006.30461 and earlier, update to a version later than 2015.006.30461 to resolve the issue.
As a temporary workaround, consider disabling the affected JavaScript APIs until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Acrobat
Reader
Reader Dc