ZeroHour

CVE-2018-4990

KEVmass

Double Free RCE in Adobe Acrobat and Reader

CISA: Adobe Acrobat and Reader Double Free Vulnerability

CVSS 3.1
8.8 high
EPSS
36%p98
Published
()
KEV added
AI analysis

CVE-2018-4990 is a double free (CWE-415) memory-corruption vulnerability in Adobe Acrobat and Reader, in which the application frees the same memory allocation twice while handling a crafted PDF document. An attacker who convinces a user on a vulnerable build to open a malicious PDF (e.g., via email attachment or web download) can corrupt heap memory and achieve remote code execution in the context of the logged-in user. Anyone running vulnerable releases of Adobe Acrobat or Reader is affected; the provided data does not enumerate specific version ranges, so unpatched builds from the disclosure era should be treated as potentially vulnerable. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-08), confirming exploitation in the wild; no public proof-of-concept is known, ransomware association is unknown, and EPSS assigns a high 36.6% probability of exploitation within 30 days.

What to do: Apply Adobe's security updates to Acrobat and Reader per vendor instructions, as required by the CISA KEV catalog, and identify any legacy or unmanaged PDF reader installs that no longer receive updates. Given the elevated EPSS score and KEV listing, prioritize patching high-value and frequently emailed endpoints, and review endpoint/mail-gateway telemetry for PDF-borne exploitation activity.

Affected
Adobe Acrobat and Reader
Estimated exposure
mass≈ hundreds of millions of users (Acrobat/Reader is the dominant desktop PDF reader; only unpatched builds are vulnerable) — Adobe Acrobat/Reader has historically been installed on hundreds of millions of end-user and enterprise desktops as the de facto PDF reader, so even a fraction of unpatched builds at disclosure represents mass exposure.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CISA Known Exploited Vulnerability
Affected
Adobe Acrobat and Reader
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
adobe
Products
acrobat dc, acrobat reader dc
Weakness
CWE-415
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news