PT-2019-5993 · Adobe · Acrobat+1
Published
2019-05-14
·
Updated
2020-08-24
·
CVE-2019-7832
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Adobe Acrobat versions prior to 2019.012.20035
Adobe Acrobat Reader versions prior to 2019.012.20035
Adobe Acrobat versions prior to 2017.011.30143
Adobe Acrobat Reader versions prior to 2017.011.30143
Adobe Acrobat versions prior to 2015.006.30498
Adobe Acrobat Reader versions prior to 2015.006.30498
Description
The issue is related to a heap overflow vulnerability and a use-after-free vulnerability in Adobe Acrobat and Reader. Successful exploitation could lead to arbitrary code execution. The vulnerability is also described as a buffer overflow in memory, which can be exploited by a remote attacker to execute arbitrary code.
Recommendations
For Adobe Acrobat and Reader versions prior to 2019.012.20035, update to a version later than 2019.012.20035.
For Adobe Acrobat and Reader versions prior to 2017.011.30143, update to a version later than 2017.011.30143.
For Adobe Acrobat and Reader versions prior to 2015.006.30498, update to a version later than 2015.006.30498.
As a temporary workaround, consider disabling the vulnerable functions until a patch is available.
Restrict access to the vulnerable modules to minimize the risk of exploitation.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acrobat
Acrobat Reader