Skip to content
COOEY

EXPOSURES › CVE-2018-4990

CVE-2018-4990

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-06-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-4990 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

A double-free vulnerability in Adobe Acrobat and Reader allowed for potential remote code execution, actively exploited in the wild and impacting DIB organizations reliant on these products.

Adobe Acrobat and Reader contained a double-free vulnerability (CVE-2018-4990) that could be exploited for remote code execution, and was actively exploited. DIB organizations using these products face potential data compromise and compliance failures (NIST 800-171 controls 3.a, 3.b, 4.a). Immediate patching and vulnerability scanning are required.

Shame score — Adobe's repeated history of critical RCE vulnerabilities in widely-used products demonstrates a pattern of insufficient security engineering and risk management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized