CVE-2019-8028: Use After Free
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .
Affected Software
Remediation
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required. Successful exploitation can result in arbitrary code execution.
Which Acrobat and Reader release branches are affected?
Affected versions include 2019.012.20035 and earlier; 2017.011.30142 and earlier; 2017.011.30143 and earlier; 2015.006.30497 and earlier; and 2015.006.30498 and earlier, for Adobe Acrobat DC and Adobe Acrobat Reader DC.
Is a fix available?
Yes. A patch is available for this vulnerability.