Vulnerability Details : CVE-2019-7112
Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .
Vulnerability category: Memory Corruption
Exploit prediction scoring system (EPSS) score for CVE-2019-7112
Probability of exploitation activity in the next 30 days: 0.53%
Percentile, the proportion of vulnerabilities that are scored at or less: ~ 74 % EPSS Score History EPSS FAQ
CVSS scores for CVE-2019-7112
Base Score | Base Severity | CVSS Vector | Exploitability Score | Impact Score | Score Source |
---|---|---|---|---|---|
10.0
|
HIGH | AV:N/AC:L/Au:N/C:C/I:C/A:C |
10.0
|
10.0
|
NIST |
9.8
|
CRITICAL | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
3.9
|
5.9
|
NIST |
CWE ids for CVE-2019-7112
-
Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.Assigned by: nvd@nist.gov (Primary)
References for CVE-2019-7112
-
https://helpx.adobe.com/security/products/acrobat/apsb19-17.html
Adobe Security BulletinPatch;Vendor Advisory
Products affected by CVE-2019-7112
- Adobe » Acrobat Dc » Classic EditionVersions from including (>=) 17.011.30056 and up to, including, (<=) 17.011.30127cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:*
- Adobe » Acrobat Dc » Continuous EditionVersions from including (>=) 15.008.20082 and up to, including, (<=) 19.010.20098cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
- Adobe » Acrobat Dc » Classic EditionVersions from including (>=) 15.006.30060 and up to, including, (<=) 15.006.30482cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:*
- Adobe » Acrobat Reader Dc » Classic EditionVersions from including (>=) 15.006.30060 and up to, including, (<=) 15.006.30482cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:*
- Adobe » Acrobat Reader Dc » Continuous EditionVersions from including (>=) 15.008.20082 and up to, including, (<=) 19.010.20098cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
- Adobe » Acrobat Reader Dc » Classic EditionVersions from including (>=) 17.011.30059 and up to, including, (<=) 17.011.30127cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:*