Use-after-free Vulnerability in Adobe Acrobat and Reader Products
CVE-2018-4996

9.8CRITICAL

Summary

Adobe Acrobat and Reader are affected by a use-after-free vulnerability, which can occur when a program attempts to use memory after it has been freed. Successful exploitation could lead to arbitrary code execution within the context of the current user. This vulnerability poses significant risks, as an attacker could potentially execute malicious code on the user's machine, compromising sensitive information or system integrity.

Affected Version(s)

Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.