CVE-2019-8161: Critical severity adobe acrobat reader dc vulnerability
Published Oct 17, 2019
·Updated
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .
Affected Software
8 affected components
Adobe Acrobat DC>=15.006.30060<15.006.30504
Adobe Acrobat DC>=15.008.20082<19.021.20047
Adobe Acrobat DC>=17.011.30059<17.011.30150
Adobe Acrobat Reader DC>=15.006.30060<15.006.30504
Adobe Acrobat Reader DC>=15.008.20082<19.021.20047
Adobe Acrobat Reader DC>=17.011.30059<17.011.30150
Apple macOS
Microsoft Windows
Remediation
Event History
Oct 17, 2019
CVE Published
via MITRE·08:11 PM
Data Sourced
via MITRE·08:11 PM
DescriptionWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The vulnerability is rated network-accessible with low attack complexity and requires no privileges or user interaction. Successful exploitation could result in arbitrary code execution.
2
Which Acrobat and Reader releases are affected?
Affected releases include version 2019.012.20040 and earlier, 2017.011.30148 and earlier, and 2015.006.30503 and earlier for Adobe Acrobat and Adobe Acrobat Reader DC.
3
Is a fix available?
Yes. A patch is available for this vulnerability.