Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-12799


Adobe Acrobat and Reader versions 2018.011.20055 and earlier, 2017.011.30096 and earlier, and 2015.006.30434 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution.


Published

2018-08-29T13:29:00.247

Last Modified

2024-11-21T03:45:50.603

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-476

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adobe acrobat_dc ≤ 15.006.30434 Yes
Application adobe acrobat_dc ≤ 18.011.20055 Yes
Application adobe acrobat_dc ≤ 17.011.30096 Yes
Application adobe acrobat_reader_dc ≤ 15.006.30434 Yes
Application adobe acrobat_reader_dc ≤ 18.011.20055 Yes
Application adobe acrobat_reader_dc ≤ 17.011.30096 Yes
Operating System apple mac_os_x - No
Operating System microsoft windows - No

References