104177vdb entry
http://www.securityfocus.com/bid/104177 CVE-2018-4993
HIGH
BADPDF Malicious PDF Creator
Record summary
CVE-2018-4993 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO hash theft vulnerability. Successful exploitation could lead to information disclosure.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions | CVE List | Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions | affected |
Proofs of concept
1Catalogued exploits
MetasploitBADPDF Malicious PDF CreatorMetasploit auxiliary PoCby Assaf Baharav +3 moreNot analyzed1 file
References
41040920vdb entry
http://www.securitytracker.com/id/1040920 helpx.adobe.com
https://helpx.adobe.com/security/products/acrobat/apsb18-09.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-4993