CVE-2019-8217: Use After Free
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .
Affected Software
Remediation
Event History
Frequently Asked Questions
What must an attacker do to exploit this vulnerability?
The attacker must cause a user to interact with malicious content. The CVSS vector indicates exploitation is network-based, requires no privileges, and has low attack complexity.
What is the impact of successful exploitation?
Successful exploitation could allow arbitrary code execution. The vulnerability is rated high severity with a CVSS 3.1 score of 8.8 and can affect confidentiality, integrity, and availability.
Which product versions are affected?
Affected versions include Acrobat and Reader 2019.012.20040 and earlier, 2017.011.30148 and earlier, and 2015.006.30503 and earlier.
What should organizations do to remediate this issue?
Apply the available patch for affected Adobe Acrobat DC and Adobe Acrobat Reader DC installations.