CVE-2019-7827
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a heap overflow vulnerability.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 13.62% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- adobe/acrobat dc · adobe/acrobat reader dc
- Source
- psirt@adobe.com
References
- http://www.securityfocus.com/bid/108325Third Party Advisory, VDB Entry
- https://helpx.adobe.com/security/products/acrobat/apsb19-18.htmlPatch, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-19-513/Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/108325Third Party Advisory, VDB Entry
- https://helpx.adobe.com/security/products/acrobat/apsb19-18.htmlPatch, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-19-513/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.