10

CVE-2018-4948

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Data is provided by the National Vulnerability Database (NVD)
AdobeAcrobat Dc SwEditionclassic Version >= 15.006.30417 < 15.006.30418
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeAcrobat Dc Version >= 17.011.30079 < 17.011.30080
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeAcrobat Dc SwEditioncontinuous Version >= 18.011.20038 < 18.011.20040
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeAcrobat Reader Dc SwEditionclassic Version >= 15.006.30417 < 15.006.30418
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeAcrobat Reader Dc Version >= 17.011.30079 < 17.011.30080
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeAcrobat Reader Dc SwEditioncontinuous Version >= 18.011.20038 < 18.011.20040
   ApplemacOS X Version-
   MicrosoftWindows Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.3% 0.884
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.