CVE-2019-8098 is a critical out-of-bounds write vulnerability affecting multiple versions of Adobe Acrobat and Reader, as well as products from Apple and Microsoft that integrate these components. With a CVSS score of 9.8, this vulnerability allows for arbitrary code execution with no user interaction required, posing a significant risk of complete system compromise. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community. Despite its high severity, it is not currently listed on the CISA KEV catalog or Hot List, suggesting it is not under active, widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.006.30060, < 15.006.30499CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 15.008.20082, < 19.012.20036CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 17.011.30059, < 17.011.30144CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 15.006.30060, < 15.006.30499CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* | ||
>= 15.008.20082, < 19.012.20036CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.