Published on: 12 December 2018
Security updates are released for Adobe Reader/Acrobat to address multiple vulnerabilities. To exploit the vulnerabilities, a remote attacker would entice a targeted user to open a specially crafted PDF file.
A successful exploitation could lead to arbitrary code execution, privilege escalation and information disclosure of an affected system.
Upgrade Adobe Reader/Acrobat to the following versions to address the issues.
Acrobat DC (Continuous) 2019.010.20064 for Windows and macOS
Acrobat Reader DC (Continuous) 2019.010.20064 for Windows and macOS
Acrobat 2017 2017.011.30110 for Windows and macOS
Acrobat Reader DC 2017 2017.011.30110 for Windows and macOS
Acrobat DC (Classic 2015) 2015.006.30461 for Windows and macOS
Acrobat Reader DC (Classic 2015) 2015.006.30461 for Windows and macOS
The upgrade can be obtained by using the auto-update mechanism or by downloading at the following URLs:
https://helpx.adobe.com/security/products/acrobat/apsb18-41.html
https://www.hkcert.org/my_url/en/alert/18121202
https://www.us-cert.gov/ncas/current-activity/2018/12/11/Adobe-Releases-Security-Updates
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12830
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15984 (to CVE-2018-16047)
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19698 (to CVE-2018-19717)
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19719 (to CVE-2018-19720)