CVE-2018-4995: Critical severity adobe acrobat reader dc vulnerability
Published Jul 9, 2018
·Updated
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an XFA '\n' POST injection vulnerability. Successful exploitation could lead to a security bypass.
Affected Software
8 affected components
Adobe Acrobat DC>=15.006.30060<=15.006.30417
Adobe Acrobat DC>=15.008.20082<=18.011.20038
Adobe Acrobat DC>=17.011.30059<=17.011.30079
Adobe Acrobat Reader DC>=15.006.30060<=15.006.30417
Adobe Acrobat Reader DC>=15.008.20082<=18.011.20038
Adobe Acrobat Reader DC>=17.011.30059<=17.011.30079
Apple iOS and macOS
Microsoft Windows
Remediation
Event History
Jul 9, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-4995?
CVE-2018-4995 is classified as having a critical severity level due to its potential to allow security bypass.
2
How do I fix CVE-2018-4995?
To fix CVE-2018-4995, update Adobe Acrobat and Reader to the latest versions that are not vulnerable.
3
What versions of Adobe software are affected by CVE-2018-4995?
CVE-2018-4995 affects Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier.
4
What type of vulnerability is CVE-2018-4995?
CVE-2018-4995 is an XFA '\n' POST injection vulnerability.
5
Could exploitation of CVE-2018-4995 be harmful?
Yes, successful exploitation of CVE-2018-4995 could lead to a security bypass, allowing unauthorized actions.