VulnerabilityModified
CVE-2018-4993
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO hash theft vulnerability.
HIGH 7.5EPSS 86.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 86.9%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO hash theft vulnerability. Successful exploitation could lead to information disclosure.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 86.90% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- adobe/acrobat dc · adobe/acrobat reader dc
- Source
- psirt@adobe.com
References
- http://www.securityfocus.com/bid/104177Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040920Third Party Advisory, VDB Entry
- https://helpx.adobe.com/security/products/acrobat/apsb18-09.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/104177Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040920Third Party Advisory, VDB Entry
- https://helpx.adobe.com/security/products/acrobat/apsb18-09.htmlPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.