SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-4921

Adobe Connect versions 9.7 and earlier have an exploitable unrestricted SWF file upload vulnerability.

MEDIUM 6.1EPSS 4.20%

Does this matter?

Lower severity and a low EPSS score (4.20%). Track it; it rarely justifies an emergency change on its own.

Description

Adobe Connect versions 9.7 and earlier have an exploitable unrestricted SWF file upload vulnerability. Successful exploitation could lead to information disclosure.

CVSS 3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
4.20% probability · 90th percentile
CISA KEV
Not listed
Weakness
CWE-434
Affected
adobe/connect
Source
psirt@adobe.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.