Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an XFA '\n' POST injection vulnerability. Successful exploitation could lead to a security bypass.
2018-07-09T19:29:03.420
2024-11-21T04:07:52.923
Modified
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | adobe | acrobat_dc | ≤ 15.006.30417 | Yes |
Application | adobe | acrobat_dc | ≤ 18.011.20038 | Yes |
Application | adobe | acrobat_dc | ≤ 17.011.30079 | Yes |
Application | adobe | acrobat_reader_dc | ≤ 15.006.30417 | Yes |
Application | adobe | acrobat_reader_dc | ≤ 18.011.20038 | Yes |
Application | adobe | acrobat_reader_dc | ≤ 17.011.30079 | Yes |
Operating System | apple | mac_os_x | - | No |
Operating System | microsoft | windows | - | No |