CVE-2018-12770 is a Use-after-free vulnerability affecting Adobe Acrobat and Reader versions 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier. This high-severity vulnerability (CVSS 8.8) allows for arbitrary code execution in the context of the current user, requiring user interaction (UI:R) but no authentication (PR:N) over a network (AV:N). While there is no evidence of active exploitation (KEV: No) or public exploit code (Metasploit, Nuclei, ExploitDB: None), it has received some community discussion and media coverage, indicating awareness. Organizations should prioritize patching affected Adobe products to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.006.30060, <= 15.006.30418CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 15.008.20082, <= 18.011.20040CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 17.011.30059, <= 17.011.30080CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 15.006.30060, <= 15.006.30418CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* | ||
>= 15.008.20082, <= 18.011.20040CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.