First published: Fri Oct 12 2018(Updated: )
Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader DC | >=15.006.30060<=15.006.30452 | |
Adobe Acrobat Reader DC | >=15.008.20082<=18.011.20063 | |
Adobe Acrobat Reader DC | >=17.011.30059<=17.011.30102 | |
Adobe Acrobat Reader | >=15.006.30060<=15.006.30452 | |
Adobe Acrobat Reader | >=15.008.20082<=18.011.20063 | |
Adobe Acrobat Reader | >=17.011.30059<=17.011.30102 | |
Apple iOS and macOS | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12833 is considered a critical vulnerability due to its capability of leading to arbitrary code execution.
To fix CVE-2018-12833, update Adobe Acrobat and Reader to the latest versions that address this vulnerability.
CVE-2018-12833 affects Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier.
If successfully exploited, CVE-2018-12833 can allow an attacker to execute arbitrary code on the affected system.
Mitigations include disabling any features of Adobe Acrobat or Reader that allow for execution of untrusted PDF files.