Back

CVE-2018-19707

CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Published: Jan 18, 2019 Modified: Jun 17, 2026
CWE-416

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (12)

Vendor Product Version
adobe acrobat_dc * ≥ 15.006.30060
adobe acrobat_dc * ≥ 15.008.20082
adobe acrobat_dc * ≥ 17.011.30056
adobe acrobat_reader_dc * ≥ 15.006.30060
adobe acrobat_reader_dc * ≥ 15.008.20082
adobe acrobat_reader_dc * ≥ 17.011.30059
adobe acrobat_dc * ≥ 15.006.30060
adobe acrobat_dc * ≥ 15.008.20082
adobe acrobat_dc * ≥ 17.011.30056
adobe acrobat_reader_dc * ≥ 15.006.30060
adobe acrobat_reader_dc * ≥ 15.008.20082
adobe acrobat_reader_dc * ≥ 17.011.30059

GitHub Security Advisory GHSA-xhmp-98v4-42g3

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 5.68%

Top 8% most likely to be exploited

Threat Score 40.9 / 100

Data Sources

NVD EPSS GitHub