CVE-2019-8226: High severity adobe acrobat reader dc vulnerability
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an incomplete implementation of security mechanism vulnerability. Successful exploitation could lead to information disclosure.
Affected Software
Remediation
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems running Adobe Acrobat DC or Adobe Acrobat Reader DC at the listed affected version levels are exposed. The affected releases include 2019.012.20040 and earlier, 2017.011.30148 and earlier, and 2015.006.30503 and earlier.
Does exploitation require authentication or user interaction?
No. The CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What is the potential impact of successful exploitation?
Successful exploitation could disclose information. The CVSS vector rates confidentiality impact as high and indicates no integrity or availability impact.
What should teams do to remediate the issue?
Apply the available patch for Adobe Acrobat DC and Adobe Acrobat Reader DC. The provided advisory reference is Adobe APSB19-49.