CVE-2019-8042
CRITICALAdobe Acrobat and Reader DC < 19.012.20036 - Out-of-bounds Write
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-8042. PoCs published by Google Security Research.
AI-analyzed exploit summary The exploit demonstrates a memory corruption vulnerability in Adobe Acrobat Reader DC's CoolType module, triggered by a malformed PDF with a crafted TrueType font stream. The crash occurs due to an access violation when writing to a negative offset relative to a heap allocation.
Description
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
Exploits (1)
The exploit demonstrates a memory corruption vulnerability in Adobe Acrobat Reader DC's CoolType module, triggered by a malformed PDF with a crafted TrueType font stream. The crash occurs due to an access violation when writing to a negative offset relative to a heap allocation.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H