Integer overflow in Adobe Reader and Adobe Acrobat - CVE-2019-8099
Published: August 13, 2019
Vulnerability identifier: #VU20141
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-8099
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to integer overflow when processing PDF files. A remote attacker can create a specially crafted PDF file, trick the victim into opening it, trigger integer overflow and gain access to sensitive information.
Affected software
Adobe Reader
Adobe Acrobat
Adobe Acrobat
How to mitigate CVE-2019-8099
Install updates from vendor's website.
Adobe Reader - addressed in versions 15.006.30499, 17.011.30144, 19.012.20036
Adobe Acrobat - addressed in versions 15.006.30499, 17.011.30144, 19.012.20036
Adobe Acrobat - addressed in versions 15.006.30499, 17.011.30144, 19.012.20036