Vulnerability record · CVE-2018-4993 · published 9 July 2018
CVE-2018-4993: Adobe Acrobat and Reader NTLM SSO hash theft information disclosure
Adobe · Acrobat Dc
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier contain an NTLM SSO hash theft vulnerability. Successful exploitation could lead to information disclosure. The flaw is rated high severity with a CVSS 3.0 score of 7.5.
Description
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO hash theft vulnerability. Successful exploitation could lead to information disclosure.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityHigh CVSS score and very high EPSS probability indicate significant risk, though no known active exploitation in KEV.
What it is
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier contain an NTLM SSO hash theft vulnerability. Successful exploitation could lead to information disclosure. The flaw is rated high severity with a CVSS 3.0 score of 7.5.
Impact
An attacker can steal NTLM SSO hashes, leading to information disclosure. This may enable further attacks such as credential relay or offline cracking.
Attack surface
The vulnerability is network-reachable (AV:N) with no privileges required (PR:N) and no user interaction (UI:N) per the CVSS vector. It is exploited through crafted PDF documents or related content processed by Adobe Acrobat or Reader.
Exploitation
The CVE is not listed in CISA KEV, but EPSS indicates a high probability of exploitation (0.8672, 99.7th percentile). References include third-party advisories and a vendor patch.
What to do
- Apply the vendor patch from Adobe security bulletin APSB18-09.
- Upgrade to the latest supported versions of Adobe Acrobat and Reader.
- Restrict network access to untrusted SMB or NTLM authentication endpoints.
- Disable NTLM authentication where possible or enforce SMB signing.
- Educate users about opening untrusted PDF files.
Detection
- Monitor for outbound SMB or NTLM authentication attempts from systems running Adobe Acrobat or Reader.
- Detect unusual processes spawning from Acrobat or Reader that initiate network connections.
- Review logs for NTLM authentication failures or relay attempts originating from user workstations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/104177 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040920 | Third Party AdvisoryVDB Entry |
| https://helpx.adobe.com/security/products/acrobat/apsb18-09.html | PatchVendor Advisory |
| http://www.securityfocus.com/bid/104177 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040920 | Third Party AdvisoryVDB Entry |
| https://helpx.adobe.com/security/products/acrobat/apsb18-09.html | PatchVendor Advisory |
Track CVE-2018-4993 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-4993), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.