CVE-2018-4990
KEVmassDouble Free RCE in Adobe Acrobat and Reader
CISA: Adobe Acrobat and Reader Double Free Vulnerability
CVE-2018-4990 is a double free (CWE-415) memory-corruption vulnerability in Adobe Acrobat and Reader, in which the application frees the same memory allocation twice while handling a crafted PDF document. An attacker who convinces a user on a vulnerable build to open a malicious PDF (e.g., via email attachment or web download) can corrupt heap memory and achieve remote code execution in the context of the logged-in user. Anyone running vulnerable releases of Adobe Acrobat or Reader is affected; the provided data does not enumerate specific version ranges, so unpatched builds from the disclosure era should be treated as potentially vulnerable. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-08), confirming exploitation in the wild; no public proof-of-concept is known, ransomware association is unknown, and EPSS assigns a high 36.6% probability of exploitation within 30 days.
What to do: Apply Adobe's security updates to Acrobat and Reader per vendor instructions, as required by the CISA KEV catalog, and identify any legacy or unmanaged PDF reader installs that no longer receive updates. Given the elevated EPSS score and KEV listing, prioritize patching high-value and frequently emailed endpoints, and review endpoint/mail-gateway telemetry for PDF-borne exploitation activity.
| Adobe Acrobat and Reader | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
- Affected
- Adobe Acrobat and Reader
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- adobe
- Products
- acrobat dc, acrobat reader dc
- Weakness
- CWE-415
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H