CVE-2019-8197
CRITICALAdobe Acrobat and Reader DC < 15.006.30504, 15.008.20082-19.021.20047 - Heap Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-8197. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates a heap-based buffer overflow in Adobe Acrobat Reader DC (2019.012.20036) via a malformed PDF file. The crash occurs due to an access violation when writing data outside a heap buffer in the JP2KLib module.
Description
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
Exploits (1)
This exploit demonstrates a heap-based buffer overflow in Adobe Acrobat Reader DC (2019.012.20036) via a malformed PDF file. The crash occurs due to an access violation when writing data outside a heap buffer in the JP2KLib module.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H