Join Us for Zenith Live 2019 Learn More
Join Us for Zenith Live 2019 Learn More

 

Security Advisory - April 09, 2019

Zscaler protects against 4 new vulnerabilities for Adobe Acrobat and Reader.

 

 

Zscaler, working with Microsoft through their MAPP program, has proactively deployed protections for the following 4 vulnerabilities included in the April 2019 Adobe security bulletins. Zscaler will continue to monitor exploits associated with all vulnerabilities in the April release and deploy additional protections as necessary.

APSB19-17 – Security updates available for Adobe Acrobat and Reader.

Adobe has released security updates for Adobe Acrobat and Reader for Windows and macOS. These updates address critical and important vulnerabilities. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Affected Software

  • Acrobat DC (Continuous) 2019.010.20098 and earlier versions for Windows and macOS
  • Acrobat Reader DC (Continuous) 2019.010.20098 and earlier versions for Windows and macOS    
  • Acrobat 2017 (Classic 2017) 2017.011.30127 and earlier version for Windows and macOS
  • Acrobat Reader 2017 (Classic 2017) 2017.011.30127 and earlier version for Windows and macOS
  • Acrobat DC (Classic 2015) 2015.006.30482 and earlier versions for Windows and macOS
  • Acrobat Reader DC (Classic 2015) 2015.006.30482 and earlier versions for Windows and macOS

CVE-2019-7061 – Out-of-Bounds Read Vulnerability leading to Information Disclosure.

Severity: Important

CVE-2019-7112 – Use After Free Vulnerability leading to Arbitrary Code Execution.

Severity: Critical

CVE-2019-7114 – Out-of-Bounds Read Vulnerability leading to Information Disclosure.

Severity: Important

CVE-2019-7125 – Heap Overflow Vulnerability leading to Arbitrary Code Execution.

Severity: Important