First published: Tue Feb 27 2018(Updated: )
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the TIFF processing in the XPS module. A successful attack can lead to sensitive data exposure.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | >=17.0<=17.011.30070 | |
Adobe Acrobat | >=-<=18.009.20050 | |
Adobe Acrobat | >=15.0<=15.006.30394 | |
Adobe Acrobat Reader | >=17.0<=17.011.30070 | |
Adobe Acrobat Reader | >=-<=18.009.20050 | |
Adobe Acrobat Reader | >=15.0<=15.006.30394 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-4907 has been classified as a critical severity vulnerability due to the potential for arbitrary code execution.
To mitigate CVE-2018-4907, update Adobe Acrobat Reader and Adobe Acrobat DC to the latest version provided by Adobe.
Adobe Acrobat Reader versions 17.011.30070 and earlier, Acrobat DC versions 18.009.20050 and earlier, and additional older versions of Acrobat are vulnerable to CVE-2018-4907.
CVE-2018-4907 is a buffer overflow vulnerability that allows for reading past the end of a target buffer, potentially leading to system compromise.
At the time of reporting, CVE-2018-4907 had indications of active exploitation in the wild, increasing the urgency of applying updates.