CVE-2018-19725
9.8
CRITICAL · CVSS 3.1 · EPSS 3.6% (pctl 89)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have a security bypass vulnerability. Successful exploitation could lead to privilege escalation.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.63% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-269 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-03-05 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| adobe | acrobat dc |
| adobe | acrobat reader dc |
| apple | mac os x |
| microsoft | windows |
References
→ the Explorer · watch your stack · NVD