CVE-2019-8197: Critical severity Adobe Acrobat DC vulnerability
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
Affected Software
Remediation
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation can be performed remotely without authentication or user interaction. Successful exploitation could result in arbitrary code execution.
Which deployments should be prioritized for remediation?
Adobe Acrobat DC and Adobe Acrobat Reader DC deployments running the listed affected releases or earlier should be prioritized, because the issue is rated critical with a CVSS score of 9.8 and can affect confidentiality, integrity, and availability.
Is a fix available?
Yes. A patch is available; update affected Adobe Acrobat DC and Adobe Acrobat Reader DC installations.