Data: CASIE
Negative Trigger
two
critical
flaws
in
Acrobat
and
Reader
that
warrant
urgent
attention
.
Officially
,
Adobe
patches
Vulnerability-related.PatchVulnerability
security
vulnerabilities
around
the
middle
of
each
month
to
coordinate
with
Microsoft
’
s
Patch
Tuesday
,
but
recently
it
’
s
become
almost
routine
for
the
company
to
issue
Vulnerability-related.PatchVulnerability
out-of-band
updates
in
between
.
APSB19-02
,
the
first
of
such
updates
to
reach
customers
in
the
new
year
,
addresses
Vulnerability-related.PatchVulnerability
critical
flaws
with
a
priority
rating
of
‘
2
’
.
That
means
that
the
flaw
is
potentially
serious
,
but
Adobe
hasn
’
t
detected
Vulnerability-related.DiscoverVulnerability
any
real-world
exploits
(
the
latter
would
entail
issuing
Vulnerability-related.PatchVulnerability
an
‘
emergency
’
patch
with
a
‘
1
’
rating
)
.
The
first
flaw
,
identified
Vulnerability-related.DiscoverVulnerability
as
CVE-2018-16011
,
is described
Vulnerability-related.DiscoverVulnerability
by
Adobe
as
a
use-after-free
bug
that
could
be exploited
Vulnerability-related.DiscoverVulnerability
using
a
maliciously
crafted
PDF
to
take
control
of
a
target
system
with
their
malware
of
choice
.
The
second
,
CVE-2018-16018
(
replacing
CVE-2018-19725
)
,
is
a
security
bypass
targeting
JavaScript
API
restrictions
on
Adobe
Reader
DC
and
seems
to
have
been
in
the
works
since
before
Christmas
,
affecting
Vulnerability-related.DiscoverVulnerability
all
versions
of
Window
and
macOS
Acrobat
DC/Reader
2019.010.20064
and
earlier
,
the
fix
in
both
cases
is
to
update
Vulnerability-related.PatchVulnerability
to
2019.010.20069
.
For
the
legacy
Acrobat/Reader
2017
2017.011.30110
and
Acrobat/Reader
DC
2015
2015.006.30461
,
the
updates
take
those
to
2017.011.30113
and
2015.006.30464
respectively
.
As
critical
flaws
with
a
‘
2
’
rating
,
there
is
a
suggested
30-day
window
within
which
to
apply
Vulnerability-related.PatchVulnerability
the
updates
,
but
it
’
s
worth
bearing
in
mind
that
a
new
round
of
patches
will
likely
be offered
Vulnerability-related.PatchVulnerability
for
Adobe
products
tomorrow
as
part
of
Patch
Tuesday
.
In
December
’
s
Patch
Tuesday
,
Adobe
released
Vulnerability-related.PatchVulnerability
a
not
inconsiderable
87
patches
,
including
39
rated
critical
.
Only
days
before
,
Adobe
issued
Vulnerability-related.PatchVulnerability
an
emergency
Flash
patch
for
a
zero-day
vulnerability
that
was
being exploited
Vulnerability-related.DiscoverVulnerability
,
while
in
November
Flash
received
Vulnerability-related.PatchVulnerability
a
separate
patch
for
one
whose
exploitation
was
believed
to
be
imminent
.