Record summary

CVE-2018-4993 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.

Description

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO hash theft vulnerability. Successful exploitation could lead to information disclosure.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions

CVE ListAdobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versionsaffected

Proofs of concept

1

Catalogued exploits

MetasploitBADPDF Malicious PDF CreatorMetasploit auxiliary PoCby Assaf Baharav +3 moreNot analyzed1 file

Ruby

Metasploit

PoC details

References

4