Korean
<< Back
VID 50185
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description Adobe Acrobat <= 15.006.30452 / 17.011.30102 / 18.011.20063 Multiple Vulnerabilities (APSB18-30)

- out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution (CVE-2018-12759, CVE-2018-12834)

- have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution (CVE-2018-12769)

- have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution. (CVE-2018-12831)

- have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution. (CVE-2018-12832, CVE-2018-12833, CVE-2018-12836, CVE-2018-12837)

- have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. (CVE-2018-12835)

- have a stack overflow vulnerability. Successful exploitation could lead to information disclosure. (CVE-2018-12838)

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these conditions will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
https://helpx.adobe.com/security/products/acrobat/apsb18-30.html

* Platforms Affected:
Adobe Acrobat versions prior to 2017.011.30102
Microsoft Windows Any version
Linux Any version
Recommendation Upgrade to the latest version of Adobe Acrobat (2017.011.30102 or later), as described in the Adobe Security bulletin at https://helpx.adobe.com/security/products/acrobat/apsb18-30.html
Related URL CVE-2018-12759,CVE-2018-12769,CVE-2018-12831,CVE-2018-12832,CVE-2018-12833,CVE-2018-12834,CVE-2018-12835,CVE-2018-12836,CVE-2018-15953 (CVE)
Related URL 105432,105435,105436,105437,105438,105439,105440,105441,105442,105443,105444 (SecurityFocus)
Related URL (ISS)