CVE-2019-8057: Use After Free
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .
Affected Software
Remediation
Event History
Frequently Asked Questions
What must an attacker do to exploit this vulnerability?
An attacker would need to induce user interaction, such as getting a user to open or otherwise interact with malicious content. The vulnerability is remotely reachable, has low attack complexity, and requires no attacker privileges.
What is the potential impact of successful exploitation?
Successful exploitation could result in arbitrary code execution. The CVSS vector indicates high impact to confidentiality, integrity, and availability.
Which product releases are affected?
Affected releases include Acrobat and Reader versions 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier.
What should organizations do to remediate this issue?
Apply the available patch for affected Adobe Acrobat DC and Adobe Acrobat Reader DC installations.