Vulnerability Name: | CVE-2018-5012 (CCN-145799) | ||||||||||||
Assigned: | 2018-07-10 | ||||||||||||
Published: | 2018-07-10 | ||||||||||||
Updated: | 2019-08-21 | ||||||||||||
Summary: | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | ||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-476 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-5012 Source: BID Type: Third Party Advisory, VDB Entry 104701 Source: CCN Type: BID-104701 Adobe Acrobat and Reader APSB18-21 Multiple Arbitrary Code Execution Vulnerabilities Source: SECTRACK Type: Third Party Advisory, VDB Entry 1041250 Source: XF Type: UNKNOWN adobe-reader-cve20185012-code-exec(145799) Source: CCN Type: Adobe Security Bulletin APSB18-21 Security Updates Available for Adobe Acrobat and Reader Source: CONFIRM Type: Vendor Advisory https://helpx.adobe.com/security/products/acrobat/apsb18-21.html Source: CCN Type: ZDI-18-618 Adobe Acrobat Pro DC ImageConversion EMF Parsing Uninitialized Pointer Remote Code Execution Vulnerability | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |