Adobe Reader DC 3D PDF Parsing Flaws Trigger Out-of-Bounds Reads
Adobe patched two out-of-bounds read vulnerabilities in Adobe Reader DC affecting version 2019.010.20099, both tied to the 2d.x3d!_LoadTIFF() processing path used to render embedded U3D 3D content inside PDF files. Tracked as CVE-2019-8010 and CVE-2019-8011, the flaws can be triggered by a crafted PDF containing malformed external texture references in embedded 3D objects, causing the sandboxed Reader process to crash under the logged-on user context.
The bugs affect Acrobat’s handling of ECMA-363 Universal 3D File Format resources, including external image and texture parsing such as PNG- and TIFF-related paths. The issue is not reachable in a default installation unless 3D content display is enabled, but it poses greater risk in environments that routinely exchange 3D PDFs, including CAD-heavy workflows where 3D viewing may be enabled by default. Adobe addressed both issues in advisory APSB19-41 after coordinated disclosure by STAR Labs.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
2 events from the most recent confirmed update back to the earliest known activity.
Adobe patches CVE-2019-8010 and CVE-2019-8011 in APSB19-41
Adobe released fixes for CVE-2019-8010 and CVE-2019-8011, addressing the out-of-bounds read vulnerabilities in Reader DC's 3D PDF rendering components. The patch was published in Adobe advisory APSB19-41.
STAR Labs reports Adobe Reader DC 3D content flaws to Adobe
STAR Labs notified Adobe of two out-of-bounds read vulnerabilities, CVE-2019-8010 and CVE-2019-8011, affecting Adobe Reader DC 2019.010.20099 in the 2d.x3d/rt3d 3D content handling path. The issues could be triggered by crafted embedded U3D content with malformed external texture references when 3D content display is enabled.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


