Junglewise Threat Intelligence

CVE-2018-4990: Adobe Acrobat and Reader Double Free Vulnerability

CVE-2018-4990 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-06-08

Technologies: Adobe Acrobat, Adobe Reader, Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

Adobe Acrobat and Reader are affected by a double free vulnerability when processing specially crafted PDF content. Successful exploitation allows an attacker to execute arbitrary code in the context of the current user.

Affected products

  • Adobe Acrobat DC / Acrobat Reader DC (Continuous) 2018.011.20038 and earlier
  • Adobe Acrobat 2017 / Acrobat Reader 2017 (Classic) 2017.011.30079 and earlier
  • Adobe Acrobat DC / Acrobat Reader DC (Classic) 2015.006.30417 and earlier

Timeline

  • 2018-05-14: disclosed: Vendor advisory published by Adobe (APSB18-09)
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-06-08: exploited: Confirmed as exploited in the wild per CISA KEV catalog entry.

Related threats