CVE-2019-8203: Use After Free
Published Oct 17, 2019
·Updated
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .
Affected Software
8 affected components
Adobe Acrobat DC>=15.006.30060<15.006.30504
Adobe Acrobat DC>=15.008.20082<19.021.20047
Adobe Acrobat DC>=17.011.30059<17.011.30150
Adobe Acrobat Reader DC>=15.006.30060<15.006.30504
Adobe Acrobat Reader DC>=15.008.20082<19.021.20047
Adobe Acrobat Reader DC>=17.011.30059<17.011.30150
Apple macOS
Microsoft Windows
Remediation
Event History
Oct 17, 2019
CVE Published
via MITRE·08:23 PM
Data Sourced
via MITRE·08:23 PM
DescriptionWeakness
Frequently Asked Questions
1
What must an attacker do to exploit this issue?
The attacker must cause a user to interact with malicious content. The vulnerability is remotely reachable, requires no privileges, and has low attack complexity.
2
What is the potential impact of successful exploitation?
Successful exploitation could result in arbitrary code execution with high impact to confidentiality, integrity, and availability.
3
Which versions should be prioritized for remediation?
Prioritize Adobe Acrobat and Reader installations at or below 2019.012.20040, 2017.011.30148, or 2015.006.30503. A patch is available.