CVE-2019-8045: Buffer Overflow
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .
Affected Software
Remediation
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability is remotely exploitable with low attack complexity and requires no privileges or user interaction, according to the CVSS vector.
What is the potential impact of successful exploitation?
Successful exploitation could result in arbitrary code execution with high impact to confidentiality, integrity, and availability.
Which product releases are affected?
Affected releases include Adobe Acrobat and Reader 2019.012.20035 and earlier; 2017.011.30142 and earlier; 2017.011.30143 and earlier; 2015.006.30497 and earlier; and 2015.006.30498 and earlier.
What should organizations do to remediate the issue?
A patch is available. Update affected Adobe Acrobat DC and Adobe Acrobat Reader DC installations to a patched release.