Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisory

Adobe Reader DC 3D PDF Parsing Flaws Trigger Out-of-Bounds Reads

Updated 1mo agoFirst seen Apr 11, 20262 sources

Adobe patched two out-of-bounds read vulnerabilities in Adobe Reader DC affecting version 2019.010.20099, both tied to the 2d.x3d!_LoadTIFF() processing path used to render embedded U3D 3D content inside PDF files. Tracked as CVE-2019-8010 and CVE-2019-8011, the flaws can be triggered by a crafted PDF containing malformed external texture references in embedded 3D objects, causing the sandboxed Reader process to crash under the logged-on user context.

The bugs affect Acrobat’s handling of ECMA-363 Universal 3D File Format resources, including external image and texture parsing such as PNG- and TIFF-related paths. The issue is not reachable in a default installation unless 3D content display is enabled, but it poses greater risk in environments that routinely exchange 3D PDFs, including CAD-heavy workflows where 3D viewing may be enabled by default. Adobe addressed both issues in advisory APSB19-41 after coordinated disclosure by STAR Labs.

Share:
Adobe Reader DC 3D PDF Parsing Flaws Trigger Out-of-Bounds Reads
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Aug 13, 20197y ago

Adobe patches CVE-2019-8010 and CVE-2019-8011 in APSB19-41

Adobe released fixes for CVE-2019-8010 and CVE-2019-8011, addressing the out-of-bounds read vulnerabilities in Reader DC's 3D PDF rendering components. The patch was published in Adobe advisory APSB19-41.

May 7, 20197y ago

STAR Labs reports Adobe Reader DC 3D content flaws to Adobe

STAR Labs notified Adobe of two out-of-bounds read vulnerabilities, CVE-2019-8010 and CVE-2019-8011, affecting Adobe Reader DC 2019.010.20099 in the 2d.x3d/rt3d 3D content handling path. The issues could be triggered by crafted embedded U3D content with malformed external texture references when 3D content display is enabled.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

3 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.