Buffer Overflow in Adobe Acrobat Reader Affects Sensitive Data Security
CVE-2018-4896

6.5MEDIUM

What is CVE-2018-4896?

A buffer overflow vulnerability exists in Adobe Acrobat Reader due to improper handling of data during the image conversion process for Enhanced Metafile Format Plus (EMF+) files. This flaw affects specific versions of the software and may allow an attacker to read beyond the allocated memory space, potentially exposing sensitive information. Users are encouraged to update their software to the latest versions to mitigate the risk associated with this vulnerability.

Affected Version(s)

Adobe Acrobat Reader 2018.009.20050 and earlier , 2017.011.30070 and earlier , 2015.006.30394 and earlier Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.