CVE-2019-8048
CRITICALAdobe Acrobat and Reader DC < 15.006.30499, 15.008.20082-19.012.20036 - Memory Corruption
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-8048. PoCs published by Google Security Research.
AI-analyzed exploit summary The exploit demonstrates an access violation in Adobe Acrobat Reader DC's CoolType.dll when processing a malformed PDF with a modified CFF font stream. The crash occurs due to an out-of-bounds write, indicating a memory corruption vulnerability.
Description
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .
Exploits (1)
The exploit demonstrates an access violation in Adobe Acrobat Reader DC's CoolType.dll when processing a malformed PDF with a modified CFF font stream. The crash occurs due to an out-of-bounds write, indicating a memory corruption vulnerability.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H