CVE-2018-4888: Use After Free
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability is an instance of a use after free vulnerability. The vulnerability is triggered by a crafted PDF file that can cause a memory access violation exception in the XFA engine because of a dangling reference left as a consequence of freeing an object in the computation that manipulates internal nodes in a graph representation of a document object model used in XFA. Successful exploitation could lead to arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-4888?
CVE-2018-4888 is considered to be a critical vulnerability due to its potential to lead to arbitrary code execution.
How do I fix CVE-2018-4888?
To fix CVE-2018-4888, users should update Adobe Acrobat Reader and Acrobat DC to the latest available version.
What impact does CVE-2018-4888 have on my system?
CVE-2018-4888 can lead to program crashes and the execution of malicious code if a user opens a specially crafted PDF.
Which versions of Adobe products are affected by CVE-2018-4888?
Adobe Acrobat Reader versions 2018.009.20050 and earlier, as well as Acrobat DC versions 2017.011.30070 and earlier, are affected by CVE-2018-4888.
What type of vulnerability is CVE-2018-4888?
CVE-2018-4888 is categorized as a use after free vulnerability.