CVE-2019-8220
9.8
CRITICAL · CVSS 3.1 · EPSS 4.1% (pctl 90)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Adobe Acrobat and Reader versions, 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.1% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-416 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-10-17 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| adobe | acrobat dc |
| adobe | acrobat reader dc |
| apple | macos |
| microsoft | windows |
References
→ the Explorer · watch your stack · NVD