CVE-2019-8200: Critical severity adobe acrobat reader dc vulnerability
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .
Affected Software
Remediation
Event History
Frequently Asked Questions
What level of attacker access is required to exploit this issue?
The CVSS vector indicates that exploitation is network-based, requires no privileges, and requires no user interaction. Successful exploitation can result in arbitrary code execution with high impact to confidentiality, integrity, and availability.
Which Acrobat and Reader releases are identified as affected?
The affected versions listed are 2019.012.20040 and earlier, 2017.011.30148 and earlier, and 2015.006.30503 and earlier for Adobe Acrobat and Adobe Acrobat Reader DC.
What should organizations do to remediate the vulnerability?
A patch is available. Update affected Adobe Acrobat DC and Adobe Acrobat Reader DC installations to a patched release.