PT-2018-13354 · Adobe · Reader Dc+2

Publicado

2018-12-17

·

Atualizado

2019-10-03

·

CVE-2018-16018

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Acrobat and Reader versions 2019.010.20064 and earlier Adobe Acrobat and Reader versions 2017.011.30110 and earlier Adobe Acrobat and Reader versions 2015.006.30461 and earlier
Description A security bypass issue exists, potentially allowing attackers to escalate privileges. The vulnerability is related to the Adobe Reader DC JavaScript API, with specific issues in ANSendForSharedReview, AnnotsString object, read-only variables, CBSharedReviewCompleteAutomation, and ANSendForFormDistribution JavaScript API restrictions bypass.
Recommendations For versions 2019.010.20064 and earlier, update to a version later than 2019.010.20064 to resolve the issue. For versions 2017.011.30110 and earlier, update to a version later than 2017.011.30110 to resolve the issue. For versions 2015.006.30461 and earlier, update to a version later than 2015.006.30461 to resolve the issue. As a temporary workaround, consider disabling the affected JavaScript APIs until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2018-16018
ZDI-18-1417
ZDI-18-1418
ZDI-18-1419
ZDI-18-1420
ZDI-19-002

Produtos afetados

Acrobat
Reader
Reader Dc