Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an XFA '\n' POST injection vulnerability. Successful exploitation could lead to a security bypass.
2018-07-09T19:29:03.420
2024-11-21T04:07:52.923
Modified
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | adobe | acrobat_dc | ≤ 15.006.30417 | Yes |
| Application | adobe | acrobat_dc | ≤ 18.011.20038 | Yes |
| Application | adobe | acrobat_dc | ≤ 17.011.30079 | Yes |
| Application | adobe | acrobat_reader_dc | ≤ 15.006.30417 | Yes |
| Application | adobe | acrobat_reader_dc | ≤ 18.011.20038 | Yes |
| Application | adobe | acrobat_reader_dc | ≤ 17.011.30079 | Yes |
| Operating System | apple | mac_os_x | - | No |
| Operating System | microsoft | windows | - | No |