Adobe Acrobat Reader DC... CVE-2018-4996 CNNVD-201807-478

10.0 AV AC AU C I A
发布: 2018-07-09
修订: 2019-08-21

### Summary A specific Javascript script embedded in a PDF file can lead to a pointer to previously freed object to be reused when opening a PDF document in Adobe Acrobat Reader DC 2018.009.20044. With careful memory manipulation, this can potentially lead to sensitive memory disclosure or arbitrary code execution. In order to trigger this vulnerability, the victim would need to open the malicious file or access a malicious web page. ### Tested Versions Adobe Acrobat Reader DC 2018.009.20044 ### Product URLs https://get.adobe.com/reader/ ### CVSSv3 Score 7.1 - CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H ### CWE CWE-416: Use After Free ### Details Adobe Acrobat Reader is the most popular and most feature-rich PDF reader. It has a big user base, is usually a default PDF reader on systems and integrates into web browsers as a plugin for rendering PDFs. As such, tricking a user into visiting a malicious web page or sending a specially crafted email attachment can be enough to trigger...

0%
暂无可用Exp或PoC
当前有6条受影响产品信息