CVE-2018-4990

HIGH KEV

Adobe Acrobat and Reader DC < 15.006.30417, 15.008.20082-18.011.20038 - Use-After-Free

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2018-4990 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 8, 2022.

Description

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

References (4)

Core 4
Core References
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1040920
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104167

Scores

CVSS v3 8.8
EPSS 0.5150
EPSS Percentile 98.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-06-08
VulnCheck KEV 2018-05-14
InTheWild.io 2018-05-14
ENISA EUVD EUVD-2018-16775
CWE
CWE-415
Status published
Products (4)
adobe/acrobat_dc 15.006.30060 - 15.006.30417
adobe/acrobat_dc 15.008.20082 - 18.011.20038
adobe/acrobat_reader_dc 15.006.30060 - 15.006.30417
adobe/acrobat_reader_dc 15.008.20082 - 18.011.20038
Published Jul 09, 2018
KEV Added Jun 08, 2022
Tracked Since Feb 18, 2026