Adobe Acrobat and Reader APSB18-21 Multiple Arbitrary Code Execution Vulnerabilities
BID:104701
CVE-2018-12754 | CVE-2018-12755 | CVE-2018-12756 | CVE-2018-12758 | CVE-2018-12760 | CVE-2018-12770 | CVE-2018-12771 | CVE-2018-12772 | CVE-2018-12773 | CVE-2018-12776 | CVE-2018-12782 | CVE-2018-12783 | CVE-2018-12784 | CVE-2018-12787 | CVE-2018-12791 | CVE-2018-12792 | CVE-2018-12793 | CVE-2018-12794 | CVE-2018-12796 | CVE-2018-12797 | CVE-2018-5009 | CVE-2018-5011 | CVE-2018-5012 | CVE-2018-5020 | CVE-2018-5021 | CVE-2018-5030 | CVE-2018-5034 | CVE-2018-5037 | CVE-2018-5042 | CVE-2018-5043 | CVE-2018-5057 | CVE-2018-5059 | CVE-2018-5064 | CVE-2018-5065 | CVE-2018-5069 | CVE-2018-5070 |Info
Adobe Acrobat and Reader APSB18-21 Multiple Arbitrary Code Execution Vulnerabilities
| Bugtraq ID: | 104701 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-12782 CVE-2018-5009 CVE-2018-5011 CVE-2018-5065 CVE-2018-12756 CVE-2018-12770 CVE-2018-12772 CVE-2018-12773 CVE-2018-12776 CVE-2018-12783 CVE-2018-12791 CVE-2018-12792 CVE-2018-12796 CVE-2018-12797 CVE-2018-5020 CVE-2018-5021 CVE-2018-5042 CVE-2018-5059 CVE-2018-5064 CVE-2018-5069 CVE-2018-5070 CVE-2018-12754 CVE-2018-12755 CVE-2018-12758 CVE-2018-12760 CVE-2018-12771 CVE-2018-12787 CVE-2018-5057 CVE-2018-12793 CVE-2018-12794 CVE-2018-5012 CVE-2018-5030 CVE-2018-5034 CVE-2018-5037 CVE-2018-5043 CVE-2018-12784 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 10 2018 12:00AM |
| Updated: | Jul 10 2018 12:00AM |
| Credit: | XuPeng of TCA/SKLCS Institute of Software Chinese Academy of Sciences and HuangZheng of Baidu Security Lab, Anonymous, Vladislav Stolyarov of Kaspersky Lab, WillJ of Tencent PC Manager via Trend Micro's Zero Day Initiative, Aleksandar Nikolic of Cisco Talo |
| Vulnerable: |
Adobe Acrobat Reader DC 2018.11.20038 Adobe Acrobat Reader DC 2018.11.20035 Adobe Acrobat Reader DC 2018.9.20050 Adobe Acrobat Reader DC 2018.9.20044 Adobe Acrobat Reader DC 2017.12.20098 Adobe Acrobat Reader DC 2017.12.20093 Adobe Acrobat Reader DC 2017.9.20058 Adobe Acrobat Reader DC 2017.9.20044 Adobe Acrobat Reader DC 2015.8.20082 Adobe Acrobat Reader DC 2015.6.30417 Adobe Acrobat Reader DC 2015.6.30416 Adobe Acrobat Reader DC 2015.6.30413 Adobe Acrobat Reader DC 2015.6.30394 Adobe Acrobat Reader DC 2015.6.30392 Adobe Acrobat Reader DC 2015.6.30355 Adobe Acrobat Reader DC 2015.6.30352 Adobe Acrobat Reader DC 2015.6.30306 Adobe Acrobat Reader DC 2015.6.30060 Adobe Acrobat Reader DC 15.23.20070 Adobe Acrobat Reader DC 15.23.20053 Adobe Acrobat Reader DC 15.20.20042 Adobe Acrobat Reader DC 15.20.20039 Adobe Acrobat Reader DC 15.17.20053 Adobe Acrobat Reader DC 15.17.20050 Adobe Acrobat Reader DC 15.16.20045 Adobe Acrobat Reader DC 15.16.20039 Adobe Acrobat Reader DC 15.10.20060 Adobe Acrobat Reader DC 15.10.20059 Adobe Acrobat Reader DC 15.9.20077 Adobe Acrobat Reader DC 15.6.30280 Adobe Acrobat Reader DC 15.6.30279 Adobe Acrobat Reader DC 15.6.30244 Adobe Acrobat Reader DC 15.6.30243 Adobe Acrobat Reader DC 15.6.30201 Adobe Acrobat Reader DC 15.6.30198 Adobe Acrobat Reader DC 15.6.30174 Adobe Acrobat Reader DC 15.6.30172 Adobe Acrobat Reader DC 15.6.30121 Adobe Acrobat Reader DC 15.6.30097 Adobe Acrobat Reader DC 2015.009.20069 Adobe Acrobat Reader DC 2015.007.20033 Adobe Acrobat Reader DC 2015.006.30094 Adobe Acrobat Reader DC 2015.006.30033 Adobe Acrobat Reader DC 15.010.20056 Adobe Acrobat Reader DC 15.006.30119 Adobe Acrobat Reader 2017.11.30079 Adobe Acrobat Reader 2017.11.30078 Adobe Acrobat Reader 2017.11.30070 Adobe Acrobat Reader 2017.11.30068 Adobe Acrobat Reader 2017.11.30066 Adobe Acrobat Reader 2017.11.30059 Adobe Acrobat DC 2018.11.20038 Adobe Acrobat DC 2018.11.20035 Adobe Acrobat DC 2018.9.20050 Adobe Acrobat DC 2018.9.20044 Adobe Acrobat DC 2017.12.20098 Adobe Acrobat DC 2017.12.20093 Adobe Acrobat DC 2017.9.20058 Adobe Acrobat DC 2017.9.20044 Adobe Acrobat DC 2015.6.30417 Adobe Acrobat DC 2015.6.30416 Adobe Acrobat DC 2015.6.30413 Adobe Acrobat DC 2015.6.30394 Adobe Acrobat DC 2015.6.30392 Adobe Acrobat DC 2015.6.30355 Adobe Acrobat DC 2015.6.30352 Adobe Acrobat DC 2015.6.30306 Adobe Acrobat DC 15.23.20070 Adobe Acrobat DC 15.23.20053 Adobe Acrobat DC 15.20.20042 Adobe Acrobat DC 15.20.20039 Adobe Acrobat DC 15.17.20053 Adobe Acrobat DC 15.17.20050 Adobe Acrobat DC 15.16.20045 Adobe Acrobat DC 15.16.20039 Adobe Acrobat DC 15.10.20060 Adobe Acrobat DC 15.10.20059 Adobe Acrobat DC 15.9.20077 Adobe Acrobat DC 15.6.30280 Adobe Acrobat DC 15.6.30279 Adobe Acrobat DC 15.6.30244 Adobe Acrobat DC 15.6.30243 Adobe Acrobat DC 15.6.30201 Adobe Acrobat DC 15.6.30198 Adobe Acrobat DC 15.6.30174 Adobe Acrobat DC 15.6.30172 Adobe Acrobat DC 15.6.30121 Adobe Acrobat DC 15.6.30097 Adobe Acrobat DC 2015.009.20069 Adobe Acrobat DC 2015.008.20082 Adobe Acrobat DC 2015.007.20033 Adobe Acrobat DC 2015.006.30094 Adobe Acrobat DC 2015.006.30060 Adobe Acrobat DC 2015.006.30033 Adobe Acrobat DC 15.010.20056 Adobe Acrobat DC 15.006.30119 Adobe Acrobat 2017.11.30079 Adobe Acrobat 2017.11.30078 Adobe Acrobat 2017.11.30070 Adobe Acrobat 2017.11.30068 Adobe Acrobat 2017.11.30066 Adobe Acrobat 2017.11.30059 |
| Not Vulnerable: |
Adobe Acrobat Reader DC 2018.11.20055 Adobe Acrobat Reader DC 2015.6.30434 Adobe Acrobat DC 2018.11.20055 Adobe Acrobat DC 2015.6.30434 Adobe Acrobat 2017.11.30096 |
Discussion
Adobe Acrobat and Reader APSB18-21 Multiple Arbitrary Code Execution Vulnerabilities
Adobe Acrobat and Reader are prone to multiple arbitrary code-execution vulnerabilities.
Successfully exploiting these issues allows attackers to execute arbitrary code in the context of the affected application. Failed exploits will result in denial-of-service conditions.
The following products and versions are vulnerable:
Adobe Acrobat DC 2015.6.30418 and prior
Adobe Acrobat Reader DC 2015.6.30418 and prior
Adobe Acrobat Reader DC 2017.11.30080 and prior
Adobe Acrobat 2017.11.30080 and prior
Adobe Acrobat Reader DC 2018.11.20040 and prior
Adobe Acrobat DC 2018.11.20040 and prior
Adobe Acrobat and Reader are prone to multiple arbitrary code-execution vulnerabilities.
Successfully exploiting these issues allows attackers to execute arbitrary code in the context of the affected application. Failed exploits will result in denial-of-service conditions.
The following products and versions are vulnerable:
Adobe Acrobat DC 2015.6.30418 and prior
Adobe Acrobat Reader DC 2015.6.30418 and prior
Adobe Acrobat Reader DC 2017.11.30080 and prior
Adobe Acrobat 2017.11.30080 and prior
Adobe Acrobat Reader DC 2018.11.20040 and prior
Adobe Acrobat DC 2018.11.20040 and prior
Exploit / POC
Adobe Acrobat and Reader APSB18-21 Multiple Arbitrary Code Execution Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Adobe Acrobat and Reader APSB18-21 Multiple Arbitrary Code Execution Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Adobe Acrobat and Reader APSB18-21 Multiple Arbitrary Code Execution Vulnerabilities
References:
References: