EXPOSURES › CVE-2018-4990
CVE-2018-4990
HIGH ⌖ ON CISA KEV · EXPLOITEDA double-free vulnerability in Adobe Acrobat and Reader allowed for potential remote code execution, actively exploited in the wild and impacting DIB organizations reliant on these products.
Adobe Acrobat and Reader contained a double-free vulnerability (CVE-2018-4990) that could be exploited for remote code execution, and was actively exploited. DIB organizations using these products face potential data compromise and compliance failures (NIST 800-171 controls 3.a, 3.b, 4.a). Immediate patching and vulnerability scanning are required.
Shame score — Adobe's repeated history of critical RCE vulnerabilities in widely-used products demonstrates a pattern of insufficient security engineering and risk management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |