CVE-2018-4923 describes an OS Command Injection vulnerability in Adobe Connect versions 9.7 and earlier. This critical flaw, with a CVSS score of 9.1, allows an unauthenticated attacker to execute arbitrary commands remotely with low attack complexity, potentially leading to arbitrary file deletion. Despite its high severity and potential for significant impact, there is no known public exploit code (Metasploit, Nuclei, ExploitDB), nor is it listed in CISA's KEV catalog. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered widespread attention or active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.7CPE matchmatch criteria | cpe:2.3:a:adobe:connect:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.