CVE-2019-8220: Adobe Acrobat DC

Critical severity, CVSS 9.8. EPSS: 4.1% chance of exploitation in the next 30 days.

Adobe Acrobat and Reader versions, 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

Affected products

  • Adobe Acrobat DC: from 15.006.30060, before 15.006.30504 (fixed in 15.006.30504); from 15.008.20082, before 19.021.20047 (fixed in 19.021.20047); from 17.011.30059, before 17.011.30150 (fixed in 17.011.30150)
  • Adobe Acrobat Reader DC: from 15.006.30060, before 15.006.30504 (fixed in 15.006.30504); from 15.008.20082, before 19.021.20047 (fixed in 19.021.20047); from 17.011.30059, before 17.011.30150 (fixed in 17.011.30150)

Published 2019-10-17. Last modified 2026-06-17.