CVE-2018-12861: Critical severity adobe acrobat reader dc vulnerability
Published Oct 12, 2018
·Updated
Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected Software
8 affected components
Adobe Acrobat DC>=15.006.30060<=15.006.30452
Adobe Acrobat DC>=15.008.20082<=18.011.20063
Adobe Acrobat DC>=17.011.30059<=17.011.30102
Adobe Acrobat Reader DC>=15.006.30060<=15.006.30452
Adobe Acrobat Reader DC>=15.008.20082<=18.011.20063
Adobe Acrobat Reader DC>=17.011.30059<=17.011.30102
Apple iOS and macOS
Microsoft Windows
Remediation
Event History
Oct 12, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-12861?
CVE-2018-12861 is rated as critical due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2018-12861?
To fix CVE-2018-12861, update Adobe Acrobat and Reader to the latest version available.
3
Which Adobe products are affected by CVE-2018-12861?
CVE-2018-12861 affects Adobe Acrobat and Reader versions prior to 2018.011.20063, 2017.011.30102, and 2015.006.30452.
4
What could happen if I don't address CVE-2018-12861?
If not addressed, CVE-2018-12861 could allow an attacker to execute arbitrary code on the affected systems.
5
Is there a workaround for CVE-2018-12861?
There are no official workarounds for CVE-2018-12861 other than applying the necessary updates.