ID:2745 - Exploit for Use-after-free in Adobe Reader and Adobe Acrobat - CVE-2018-12863

 
Main Vulnerability Database Exploits ID:2745 - Exploit for Use-after-free in Adobe Reader and Adobe Acrobat - CVE-2018-12863

ID:2745 - Exploit for Use-after-free in Adobe Reader and Adobe Acrobat - CVE-2018-12863

Published: May 18, 2020


Vulnerability identifier: #VU15130
Vulnerability risk: High
CVE-ID: CVE-2018-12863
CWE-ID: CWE-416
Exploitation vector: Remote access
Vulnerable software:
Adobe Reader
Adobe Acrobat

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing PDF files. A remote attacker can create a specially crafted PDF document, trick the victim into opening it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install updates from vendor's website.