Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
The product calls free() twice on the same memory address.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Acrobat_dc | Adobe | 15.006.30060 (including) | 15.006.30417 (including) |
Acrobat_dc | Adobe | 15.008.20082 (including) | 18.011.20038 (including) |
Acrobat_dc | Adobe | 17.011.30059 (including) | 17.011.30079 (including) |
Acrobat_reader_dc | Adobe | 15.006.30060 (including) | 15.006.30417 (including) |
Acrobat_reader_dc | Adobe | 15.008.20082 (including) | 18.011.20038 (including) |
Acrobat_reader_dc | Adobe | 17.011.30059 (including) | 17.011.30079 (including) |