LiveActive security incident?Get immediate response
CVE Record

CVE-2019-19817: The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnn...

The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x2e8a Out-of-Bounds Read via crafted Unicode content.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

A malformed PDF can trigger an out-of-bounds read in Nitro Free PDF Reader 12.0.0.112. The sources do not provide CVSS, a confirmed patch, or active exploitation evidence. Treat this as a document-handling risk for users who open PDFs from email, web downloads, or external parties.

Executive priority

Handle as a moderate endpoint hygiene issue, not an emergency exploitation event based on available evidence. The main business risk is user exposure to malicious documents on older Nitro Reader installations. Prioritize discovery and upgrade decisions where external PDF handling is routine.

Technical view

CVE-2019-19817 is reported in the JBIG2Decode library inside npdf.dll. The vulnerable path is described as CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x2e8a, reached through crafted Unicode content. The public record identifies Nitro Free PDF Reader 12.0.0.112; broader version impact is not established in the provided sources.

Likely exposure

Exposure is most likely on endpoints where Nitro Free PDF Reader 12.0.0.112 is installed and users open untrusted PDF files. The provided sources do not identify server-side exposure, cloud services, or affected Nitro versions beyond the named release.

Exploitation context

No CISA KEV listing or cited source indicates active exploitation. The issue appears to require a crafted PDF or crafted content handled by the PDF reader. Public details are limited and should not be treated as proof of reliable code execution.

Researcher notes

The source bundle lacks CVSS, CWE mapping, patch status, and vendor advisory detail. The affected product metadata is incomplete, but the description names Nitro Free PDF Reader 12.0.0.112. Do not generalize impact across Nitro products without additional vendor confirmation.

Mitigation direction

  • Inventory endpoints for Nitro Free PDF Reader 12.0.0.112.
  • Check Nitro vendor guidance for fixed versions or supported upgrade paths.
  • Prioritize upgrade or removal on systems handling external PDFs.
  • Use email and web controls to reduce delivery of suspicious PDF files.
  • Restrict PDF opening for high-risk users until vendor guidance is confirmed.

Validation and detection

  • Confirm installed Nitro PDF Reader versions through endpoint inventory.
  • Review vulnerability scanner results for CVE-2019-19817 coverage.
  • Verify whether Nitro guidance names this CVE or related 2019 fixes.
  • Check EDR and helpdesk records for Nitro crashes on suspicious PDFs.
  • Document any compensating controls for users processing external documents.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2019-19817 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.