CVE-2019-7761
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.2%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 10.22% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- adobe/acrobat dc · adobe/acrobat reader dc
- Source
- psirt@adobe.com
References
- http://www.securityfocus.com/bid/108320Third Party Advisory, VDB Entry
- https://helpx.adobe.com/security/products/acrobat/apsb19-18.htmlPatch, Vendor Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0778Exploit, Third Party Advisory
- http://www.securityfocus.com/bid/108320Third Party Advisory, VDB Entry
- https://helpx.adobe.com/security/products/acrobat/apsb19-18.htmlPatch, Vendor Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0778Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.