SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-4993

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO hash theft vulnerability.

HIGH 7.5EPSS 86.9%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 86.9%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO hash theft vulnerability. Successful exploitation could lead to information disclosure.

CVSS 3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
86.90% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
adobe/acrobat dc · adobe/acrobat reader dc
Source
psirt@adobe.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.