Korean
<< Back
VID 50277
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description The version of Adobe Reader installed on the remote Windows host is a version prior or equal to 2015.006.30503, 2017.011.30148, or 2019.012.20040. It is, therefore, affected by multiple vulnerabilities.

- Out-of-Bounds Read potentially leading to Information Disclosure (CVE-2019-8064, CVE-2019-8163, CVE-2019-8164, CVE-2019-8168, CVE-2019-8172, CVE-2019-8173, CVE-2019-8182, CVE-2019-8184, CVE-2019-8185, CVE-2019-8189, CVE-2019-8190, CVE-2019-8193, CVE-2019-8194, CVE-2019-8198, CVE-2019-8201, CVE-2019-8202, CVE-2019-8204, CVE-2019-8207, CVE-2019-8216, CVE-2019-8218, CVE-2019-8222)

- Out-of-Bounds Write potentially leading to Arbitrary Code Execution (CVE-2019-8165, CVE-2019-8171, CVE-2019-8186, CVE-2019-8191, CVE-2019-8199, CVE-2019-8206)

- Use After Free potentially leading to Arbitrary Code Execution (CVE-2019-8175, CVE-2019-8176, CVE-2019-8177, CVE-2019-8178, CVE-2019-8179, CVE-2019-8180, CVE-2019-8181, CVE-2019-8187, CVE-2019-8188, CVE-2019-8192, CVE-2019-8203, CVE-2019-8208, CVE-2019-8209, CVE-2019-8210, CVE-2019-8211, CVE-2019-8212, CVE-2019-8213, CVE-2019-8214, CVE-2019-8215, CVE-2019-8217, CVE-2019-8219, CVE-2019-8220, CVE-2019-8221, CVE-2019-8223, CVE-2019-8224, CVE-2019-8225)

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these conditions will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
https://helpx.adobe.com/security/products/acrobat/apsb19-49

* Platforms Affected:
Adobe Reader versions prior equal to 2019.012.20040
Microsoft Windows Any version
Linux Any version
Recommendation Upgrade to the latest version of Adobe Reader (2019.012.20040 later), as described in the Adobe Security bulletin at https://helpx.adobe.com/security/products/acrobat/apsb19-49
Related URL CVE-2019-8064,CVE-2019-8160,CVE-2019-8161,CVE-2019-8162,CVE-2019-8163,CVE-2019-8164,CVE-2019-8165,CVE-2019-8166,CVE-2019-8167,CVE-2019-8168 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)