CVE-2018-4990
HIGH KEVAdobe Acrobat and Reader DC < 15.006.30417, 15.008.20082-18.011.20038 - Use-After-Free
Title source: llmExploitation Summary
CVE-2018-4990 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 8, 2022.
Description
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
References (4)
Core 4
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-4990
Vendor Advisory x_refsource_misc
https://helpx.adobe.com/security/products/acrobat/apsb18-09.html
Broken Link, Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1040920
Broken Link, Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/104167
Scores
CVSS v3
8.8
EPSS
0.5150
EPSS Percentile
98.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
active
Automatable
no
Technical Impact
total
Details
CISA KEV
2022-06-08
VulnCheck KEV
2018-05-14
InTheWild.io
2018-05-14
ENISA EUVD
EUVD-2018-16775
CWE
CWE-415
Status
published
Products (4)
adobe/acrobat_dc
15.006.30060 - 15.006.30417
adobe/acrobat_dc
15.008.20082 - 18.011.20038
adobe/acrobat_reader_dc
15.006.30060 - 15.006.30417
adobe/acrobat_reader_dc
15.008.20082 - 18.011.20038
Published
Jul 09, 2018
KEV Added
Jun 08, 2022
Tracked Since
Feb 18, 2026