First published: Tue Feb 27 2018(Updated: )
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs because of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion engine that handles Enhanced Metafile Format (EMF). A successful attack can lead to sensitive data exposure.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | >17.0<=17.011.30070 | |
Adobe Acrobat | >=-<=18.009.20050 | |
Adobe Acrobat | >=15.0<=15.006.30394 | |
Adobe Acrobat Reader | >=17.0<=17.011.30070 | |
Adobe Acrobat Reader | >=-<=18.009.20050 | |
Adobe Acrobat Reader | >=15.0<=15.006.30394 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-4883 has been classified with a critical severity rating due to its potential to allow arbitrary code execution.
To remediate CVE-2018-4883, update Adobe Acrobat Reader and Adobe Acrobat DC to the latest versions as recommended by Adobe.
CVE-2018-4883 affects Adobe Acrobat Reader 2018.009.20050 and earlier, Adobe Acrobat DC versions prior to 18.009.20050, and older versions of Adobe Acrobat.
Yes, CVE-2018-4883 can be exploited remotely, potentially allowing an attacker to execute arbitrary code on the victim's system.
The potential impacts of CVE-2018-4883 include file corruption, data loss, and unauthorized access to system resources.