CVE-2018-4902: Use After Free
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the rendering engine. The vulnerability is triggered by a crafted PDF file containing a video annotation (and corresponding media files) that is activated by the embedded JavaScript. Successful exploitation could lead to arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-4902?
CVE-2018-4902 is rated as a critical vulnerability due to its potential impact on affected systems.
How do I fix CVE-2018-4902?
To fix CVE-2018-4902, update Adobe Acrobat Reader and Adobe Acrobat DC to the latest version available.
What types of products are affected by CVE-2018-4902?
CVE-2018-4902 affects Adobe Acrobat Reader and Adobe Acrobat DC versions prior to the specified updates.
What does CVE-2018-4902 exploit in Adobe Acrobat?
CVE-2018-4902 exploits a use after free vulnerability in the rendering engine of Adobe Acrobat.
Can CVE-2018-4902 lead to remote code execution?
Yes, CVE-2018-4902 can potentially allow an attacker to execute arbitrary code on a user's system.