CVE Vulnerabilities

CVE-2018-19725

Improper Privilege Management

Published: Mar 05, 2019 | Modified: Oct 10, 2019
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have a security bypass vulnerability. Successful exploitation could lead to privilege escalation.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Acrobat_dc Adobe 15.006.30060 (including) 15.006.30464 (including)
Acrobat_dc Adobe 15.008.20082 (including) 19.010.20069 (including)
Acrobat_dc Adobe 17.011.30056 (including) 17.011.30113 (including)
Acrobat_reader_dc Adobe 15.006.30060 (including) 15.006.30464 (including)
Acrobat_reader_dc Adobe 15.008.20082 (including) 19.010.20069 (including)
Acrobat_reader_dc Adobe 17.011.30059 (including) 17.011.30113 (including)

Potential Mitigations

References