PT-2018-16615 · Adobe · Acrobat Reader

Published

2018-02-13

·

Updated

2020-08-24

·

CVE-2018-4910

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Acrobat Reader versions 2018.009.20050 and earlier Adobe Acrobat Reader versions 2017.011.30070 and earlier Adobe Acrobat Reader versions 2015.006.30394 and earlier
Description The issue is a heap overflow vulnerability in the JavaScript engine, triggered by a PDF file with crafted JavaScript code that manipulates the optional content group (OCG). This can lead to code corruption, control-flow hijack, or a code re-use attack, allowing attackers to execute arbitrary code.
Recommendations For Adobe Acrobat Reader versions 2018.009.20050 and earlier, update to a version later than 2018.009.20050 to resolve the issue. For Adobe Acrobat Reader versions 2017.011.30070 and earlier, update to a version later than 2017.011.30070 to resolve the issue. For Adobe Acrobat Reader versions 2015.006.30394 and earlier, update to a version later than 2015.006.30394 to resolve the issue. As a temporary workaround, consider disabling JavaScript execution in Adobe Acrobat Reader until a patch is available.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-4910
ZDI-18-173

Affected Products

Acrobat Reader