PT-2018-13354 · Adobe · Reader Dc+2

Published

2018-12-17

·

Updated

2019-10-03

·

CVE-2018-16018

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Acrobat and Reader versions 2019.010.20064 and earlier Adobe Acrobat and Reader versions 2017.011.30110 and earlier Adobe Acrobat and Reader versions 2015.006.30461 and earlier
Description A security bypass issue exists, potentially allowing attackers to escalate privileges. The vulnerability is related to the Adobe Reader DC JavaScript API, with specific issues in ANSendForSharedReview, AnnotsString object, read-only variables, CBSharedReviewCompleteAutomation, and ANSendForFormDistribution JavaScript API restrictions bypass.
Recommendations For versions 2019.010.20064 and earlier, update to a version later than 2019.010.20064 to resolve the issue. For versions 2017.011.30110 and earlier, update to a version later than 2017.011.30110 to resolve the issue. For versions 2015.006.30461 and earlier, update to a version later than 2015.006.30461 to resolve the issue. As a temporary workaround, consider disabling the affected JavaScript APIs until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-16018
ZDI-18-1417
ZDI-18-1418
ZDI-18-1419
ZDI-18-1420
ZDI-19-002

Affected Products

Acrobat
Reader
Reader Dc