CVE-2019-7079: Critical severity adobe acrobat reader dc vulnerability
Published May 24, 2019
·Updated
Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .
Affected Software
8 affected components
Adobe Acrobat DC>=15.006.30060<15.006.30475
Adobe Acrobat DC>=15.008.20082<19.010.20091
Adobe Acrobat DC>=17.011.30059<17.011.30120
Adobe Acrobat Reader DC>=15.006.30060<15.006.30475
Adobe Acrobat Reader DC>=15.008.20082<19.010.20091
Adobe Acrobat Reader DC>=17.011.30059<17.011.30120
Apple iOS and macOS
Microsoft Windows
Remediation
Event History
May 24, 2019
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What does an attacker need to do to exploit this issue?
The attacker needs to persuade a user to interact with malicious content. The vulnerability is remotely reachable and requires no attacker privileges.
2
What could successful exploitation allow?
Successful exploitation could result in arbitrary code execution with high impact to confidentiality, integrity, and availability.
3
Which installations should be prioritized for remediation?
Adobe Acrobat DC and Adobe Acrobat Reader DC installations at or below the listed affected versions should be prioritized. A patch is available.