PT-2018-13354 · Adobe · Reader Dc+2
Published
2018-12-17
·
Updated
2019-10-03
·
CVE-2018-16018
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Acrobat and Reader versions 2019.010.20064 and earlier
Adobe Acrobat and Reader versions 2017.011.30110 and earlier
Adobe Acrobat and Reader versions 2015.006.30461 and earlier
Description
A security bypass issue exists, potentially allowing attackers to escalate privileges. The vulnerability is related to the Adobe Reader DC JavaScript API, with specific issues in
ANSendForSharedReview, AnnotsString object, read-only variables, CBSharedReviewCompleteAutomation, and ANSendForFormDistribution JavaScript API restrictions bypass.Recommendations
For versions 2019.010.20064 and earlier, update to a version later than 2019.010.20064 to resolve the issue.
For versions 2017.011.30110 and earlier, update to a version later than 2017.011.30110 to resolve the issue.
For versions 2015.006.30461 and earlier, update to a version later than 2015.006.30461 to resolve the issue.
As a temporary workaround, consider disabling the affected JavaScript APIs until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Acrobat
Reader
Reader Dc