Vulnerability record · CVE-2018-4990 · published 9 July 2018
CVE-2018-4990: Adobe Acrobat and Reader double free allows code execution
Adobe · Acrobat Dc
Adobe Acrobat and Reader contain a double free (CWE-415) in versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier. Successful exploitation can execute arbitrary code in the context of the current user. The flaw is remotely reachable and requires user interaction, making it a realistic client-side attack vector.
Description
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and KEV-listed known exploitation, though it requires user interaction and a patch has long been available.
What it is
Adobe Acrobat and Reader contain a double free (CWE-415) in versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier. Successful exploitation can execute arbitrary code in the context of the current user. The flaw is remotely reachable and requires user interaction, making it a realistic client-side attack vector.
Impact
An attacker who gets a crafted file opened can run arbitrary code with the privileges of the logged-in user, enabling data theft, further compromise of the host, or installation of additional malware.
Attack surface
Reached over the network (AV:N) with no privileges required (PR:N) but requires user interaction (UI:R), typically opening a malicious PDF or document in Acrobat or Reader. No authentication is needed to trigger the flaw.
Exploitation
Listed in CISA KEV since 2022-06-08, indicating known exploitation in the wild; EPSS 30-day probability is 0.36228 (98.4th percentile), a high likelihood of exploitation activity. No ransomware campaign use is documented.
What to do
- Apply the vendor updates referenced in Adobe security bulletin APSB18-09 for Acrobat and Reader.
- Upgrade to a supported Acrobat/Reader release; the affected 2015, 2017 and 2018 branches are end-of-life.
- Disable or restrict JavaScript and non-essential PDF features in Reader where operationally feasible.
- Block untrusted PDF attachments at email and web gateways and enforce Mark-of-the-Web/Protected View style controls.
- Track KEV remediation deadlines and verify patched versions across endpoints.
Detection
- Monitor for Acrobat/Reader processes spawning child processes such as cmd.exe, powershell.exe or script hosts.
- Alert on Acrobat/Reader crashes or double-free style memory corruption events in endpoint telemetry.
- Hunt for PDF files written to temp or user directories shortly before suspicious process creation.
- Review proxy and email logs for PDFs from untrusted senders or newly registered domains.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-4990 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Adobe Acrobat and Reader Double Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/104167 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040920 | Broken LinkThird Party AdvisoryVDB Entry |
| https://helpx.adobe.com/security/products/acrobat/apsb18-09.html | Vendor Advisory |
| http://www.securityfocus.com/bid/104167 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040920 | Broken LinkThird Party AdvisoryVDB Entry |
| https://helpx.adobe.com/security/products/acrobat/apsb18-09.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-4990 | Third Party AdvisoryUS Government Resource |
Track CVE-2018-4990 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-4990), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.