CVE-2018-4917 is a critical heap overflow vulnerability affecting Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, and 2015.006.30394 and earlier, impacting systems running Adobe, Apple, and Microsoft products. With a CVSS score of 9.8, this vulnerability is easily exploitable over a network with low complexity, potentially leading to arbitrary code execution with full confidentiality, integrity, and availability impact. Despite its high severity, there is no evidence of active exploitation, no public exploit code available (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 17.011.30070, < 17.011.30078CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_2017:*:*:*:*:*:*:*:* | ||
>= 15.006.30394, < 15.006.30413CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 18.009.20050, < 18.011.20035CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 17.011.30070, < 17.011.30078CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_2017:*:*:*:*:*:*:*:* | ||
>= 15.006.30394, < 15.006.30413CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.