CVE-2018-4990: Adobe Acrobat and Reader Double Free Vulnerability
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Other sources
Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-4990?
CVE-2018-4990 is a Double Free vulnerability found in Adobe Acrobat and Reader.
How severe is CVE-2018-4990?
CVE-2018-4990 has a severity score of 8.8 (high).
Which versions of Adobe Acrobat and Reader are affected by CVE-2018-4990?
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier are affected.
What is the potential impact of CVE-2018-4990?
Successful exploitation of CVE-2018-4990 could lead to arbitrary code execution in the context of the current user.
Where can I find more information about CVE-2018-4990?
You can find more information about CVE-2018-4990 on the following URLs: http://www.securityfocus.com/bid/104167, http://www.securitytracker.com/id/1040920, and https://helpx.adobe.com/security/products/acrobat/apsb18-09.html.