CVE-2018-4967 is an Out-of-bounds read vulnerability affecting Adobe Acrobat and Reader across multiple versions, as well as products from Apple and Microsoft. This vulnerability carries a high CVSS score of 7.5, indicating a significant risk, and could lead to information disclosure if successfully exploited. While the attack vector is network-based and requires no user interaction, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on the CISA KEV catalog. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness despite its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.006.30417, < 15.006.30418CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 17.011.30079, < 17.011.30080CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:*:*:*:* | ||
>= 18.011.20038, < 18.011.20040CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 15.006.30417, < 15.006.30418CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* | ||
>= 17.011.30079, < 17.011.30080CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.