CVE-2018-12840 is an out-of-bounds read vulnerability affecting Adobe Acrobat and Reader across multiple versions (2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier), impacting systems running Adobe, Apple, and Microsoft products. This high-severity vulnerability (CVSS 7.5) has a low attack complexity and does not require user interaction, potentially leading to significant information disclosure. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered notable community discussion and media coverage, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.006.30060, <= 15.006.30448CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 15.008.20082, <= 18.011.20058CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 17.011.30059, <= 17.011.30099CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 15.006.30060, <= 15.006.30448CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* | ||
>= 15.008.20082, <= 18.011.20058CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.