BlackTreeCVE Intelligence
← Back to the CVE catalogue
Full vulnerability report · 2018
CVE-2018-4990High confidence

Adobe Acrobat and Reader Double Free Vulnerability

Adobe · Acrobat and Reader

8.8HighCVSS 3.1
Recommended action
Protect now

CISA confirms exploitation in the wild and lists 2022-06-22 as the remediation due date.

Fix not verified
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Select the national-authority views to include. The exact source language is shown on each matched advisory. Your choice is remembered on this device and encoded in the shareable URL.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2018-16775

CISA KEV mirrored by ENISA

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

EUVD state
Present in the current official mapping
Known exploitation
Recorded by ENISA since 8 Jun 2022. Evidence sources: cisa_kev.
ENISA score
8.8 · CVSS 3.1
Advisory evidence
No linked advisory details stored yet
Recommended actionProtect now

CISA confirms exploitation in the wild and lists 2022-06-22 as the remediation due date.

Fix not verified
01

What, why and how

Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.

What

Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.

Why

The product calls free() twice on the same memory address.

How

An attacker operating through a network path may attempt exploitation without authentication after a user interaction. If successful, the issue may execute code or commands in the affected security context.

What

Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.

Why

The product calls free() twice on the same memory address.

How

An attacker operating through a network path may attempt exploitation without authentication after a user interaction. If successful, the issue may execute code or commands in the affected security context.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
Confirmed in the wild

CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2022-06-08.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
None recorded

No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.

Likely attack path
a network path → Double Free → execute code or commands in the affected security context
Attack surface
Network
Privileges required
None: unauthenticated exploitation is possible
User interaction
Required interaction required
Attack complexity
Low: no specialised conditions are recorded
Security boundary
Unchanged: impact remains within the vulnerable component's security authority
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-415

CWE-415: Double Free. The product calls free() twice on the same memory address.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVNetworkAttack vector: The vulnerable component can be reached over a network.ACLowAttack complexity: No specialised conditions are required beyond attacker-controlled input.PRNonePrivileges required: The attacker does not need an account or existing privileges.UIRequiredUser interaction: Another user must perform an action for exploitation to succeed.SUnchangedScope: The security impact remains within the vulnerable component's authority.CHighConfidentiality impact: A successful attack can cause a major loss.IHighIntegrity impact: A successful attack can cause a major loss.AHighAvailability impact: A successful attack can cause a major loss.
Post-exploitation / living off the land
After compromise, an attacker may use built-in shells, scripting engines, scheduled tasks and native network utilities for discovery, persistence or movement. This is a plausible LoTL path, not evidence that it has occurred for every attack.
NetworkUnauthenticatedRemote code executionCWE-415CISA KEV
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

ENISA EUVD · EUVD-2018-16775Known-exploited evidence recorded

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Official EUVD record ↗
Canadian Centre for Cyber Security · English · AV18-081Adobe security bulletins

Number: AV18-081 Date: 14 May 2018 Purpose The purpose of this advisory is to bring attention to recently published Adobe security bulletins. Assessment Adobe has released security updates for Adobe Photoshop, Adobe Acrobat and Acrobat Reader for Windows and MacOS. Affected products: - Acrobat DC & 2017 - Acrobat Reader DC & 2017 - Photoshop CC 2017 & 2018 CVE References: CVE-2018-4990, CVE-2018-4947, CVE-2018-4948, CVE-2018-4966, CVE-2018-4968, CVE-2018-4978, CVE-2018-4982, CVE-2018-4984, CVE-2018-4946, CVE-2018-4952, CVE-2018-4954, CVE-2018-4958, CVE-2018-4959, CVE-2018-4961, CVE-2018-4971, CVE-2018-4974, CVE-2018-4977, CVE-2018-4980, CVE-2018-4983, CVE-2018-4988, CVE-2018-4989, CVE-2018-4950, CVE-2018-4979, CVE-2018-4949, CVE-2018-4951, CVE-2018-4955, CVE-2018-4956, CVE-2018-4957, CVE-2018-4960, CVE-2018-4962, CVE-2018-4963, CVE-2018-4964, CVE-2018-4967, CVE-2018-4969, CVE-2018-4970, CVE-2018-4972, CVE-2018-4973, CVE-2018-4975, CVE-2018-4976, CVE-2018-4981, CVE-2018-4986, CVE-2018-4985, CVE-2018-4953, CVE-2018-4987, CVE

Official advisory ↗
CERT-FR · French · CERTFR-2018-AVI-233Multiples vulnérabilités dans Adobe Reader et Acrobat

.cve.org/CVERecord?id=CVE-2018-4981 Référence CVE CVE-2018-4982 https://www.cve.org/CVERecord?id=CVE-2018-4982 Référence CVE CVE-2018-4983 https://www.cve.org/CVERecord?id=CVE-2018-4983 Référence CVE CVE-2018-4984 https://www.cve.org/CVERecord?id=CVE-2018-4984 Référence CVE CVE-2018-4985 https://www.cve.org/CVERecord?id=CVE-2018-4985 Référence CVE CVE-2018-4986 https://www.cve.org/CVERecord?id=CVE-2018-4986 Référence CVE CVE-2018-4987 https://www.cve.org/CVERecord?id=CVE-2018-4987 Référence CVE CVE-2018-4988 https://www.cve.org/CVERecord?id=CVE-2018-4988 Référence CVE CVE-2018-4989 https://www.cve.org/CVERecord?id=CVE-2018-4989 Référence CVE CVE-2018-4990 https://www.cve.org/CVERecord?id=CVE-2018-4990 Référence CVE CVE-2018-4993 https://www.cve.org/CVERecord?id=CVE-2018-4993 Référence CVE CVE-2018-4994 https://www.cve.org/CVERecord?id=CVE-2018-4994 Gestion détaillée du document le 14 mai 2018 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr france.fr info.gouv.fr/risques Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la sécurité des systèmes d'information

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-007454Adobe Reader および Acrobat における型の取り違えの脆弱性

Adobe Reader および Acrobat には、型の取り違えの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006782Adobe Reader および Acrobat におけるヒープオーバーフローの脆弱性

Adobe Reader および Acrobat には、ヒープオーバーフローの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006778Adobe Reader および Acrobat における解放済みメモリを使用される脆弱性

Adobe Reader および Acrobat には、解放済みメモリを使用される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006777Adobe Reader および Acrobat における解放済みメモリを使用される脆弱性

Adobe Reader および Acrobat には、解放済みメモリを使用される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006776Adobe Reader および Acrobat における解放済みメモリを使用される脆弱性

Adobe Reader および Acrobat には、解放済みメモリを使用される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006775Adobe Reader および Acrobat における信頼できないポインタのデリファレンスの脆弱性

Adobe Reader および Acrobat には、信頼できないポインタのデリファレンスの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006774Adobe Reader および Acrobat における解放済みメモリを使用される脆弱性

Adobe Reader および Acrobat には、解放済みメモリを使用される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006764Adobe Reader および Acrobat における解放済みメモリを使用される脆弱性

Adobe Reader および Acrobat における解放済みメモリを使用される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006763Adobe Reader および Acrobat における XFA '\n' POST インジェクションの脆弱性

Adobe Reader および Acrobat には、XFA '\n' POST インジェクションの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006761Adobe Reader および Acrobat における解放済みメモリを使用される脆弱性

Adobe Reader および Acrobat には、解放済みメモリを使用される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006760Adobe Reader および Acrobat における解放済みメモリを使用される脆弱性

Adobe Reader および Acrobat には、解放済みメモリを使用される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006757Adobe Reader および Acrobat におけるヒープオーバーフローの脆弱性

Adobe Reader および Acrobat には、ヒープオーバーフローの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006755Adobe Reader および Acrobat におけるヒープオーバーフローの脆弱性

Adobe Reader および Acrobat には、ヒープオーバーフローの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006754Adobe Reader および Acrobat における解放済みメモリを使用される脆弱性

Adobe Reader および Acrobat には、解放済みメモリを使用される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006749Adobe Reader および Acrobat におけるヒープオーバーフローの脆弱性

Adobe Reader および Acrobat には、ヒープオーバーフローの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006747Adobe Reader および Acrobat における境界外書き込みの脆弱性

Adobe Reader および Acrobat には、境界外書き込みの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006736Adobe Reader および Acrobat におけるヒープオーバーフローの脆弱性

Adobe Reader および Acrobat には、ヒープオーバーフローの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006735Adobe Reader および Acrobat におけるヒープオーバーフローの脆弱性

Adobe Reader および Acrobat には、ヒープオーバーフローの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006781Adobe Reader および Acrobat における解放済みメモリを使用される脆弱性

Adobe Reader および Acrobat には、解放済みメモリを使用される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006780Adobe Reader および Acrobat における型の取り違えの脆弱性

Adobe Reader および Acrobat には、型の取り違えの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006779Adobe Reader および Acrobat における解放済みメモリを使用される脆弱性

Adobe Reader および Acrobat には、解放済みメモリを使用される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006773Adobe Reader および Acrobat におけるヒープオーバーフローの脆弱性

Adobe Reader および Acrobat には、ヒープオーバーフローの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006772Adobe Reader および Acrobat における解放済みメモリを使用される脆弱性

Adobe Reader および Acrobat には、解放済みメモリを使用される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006770Adobe Reader および Acrobat における解放済みメモリを使用される脆弱性

Adobe Reader および Acrobat には、解放済みメモリを使用される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006768Adobe Reader および Acrobat における解放済みメモリを使用される脆弱性

Adobe Reader および Acrobat には、解放済みメモリを使用される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006762Adobe Reader および Acrobat における NTLM SSO ハッシュを盗用される脆弱性

Adobe Reader および Acrobat には、NTLM SSO ハッシュを盗用される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006759Adobe Reader および Acrobat における境界外読み取りの脆弱性

Adobe Reader および Acrobat には、境界外読み取りの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006758Adobe Reader および Acrobat における境界外読み取りの脆弱性

Adobe Reader および Acrobat には、境界外読み取りの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006756Adobe Reader および Acrobat における境界外読み取りの脆弱性

Adobe Reader および Acrobat には、境界外読み取りの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006753Adobe Reader および Acrobat における境界外読み取りの脆弱性

Adobe Reader および Acrobat には、境界外読み取りの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006752Adobe Reader および Acrobat における境界外読み取りの脆弱性

Adobe Reader および Acrobat には、境界外読み取りの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006751Adobe Reader および Acrobat における境界外読み取りの脆弱性

Adobe Reader および Acrobat には、境界外読み取りの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006750Adobe Reader および Acrobat における境界外読み取りの脆弱性

Adobe Reader および Acrobat には、境界外読み取りの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006748Adobe Reader および Acrobat における境界外読み取りの脆弱性

Adobe Reader および Acrobat には、境界外読み取りの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006745Adobe Reader および Acrobat における境界外読み取りの脆弱性

Adobe Reader および Acrobat には、境界外読み取りの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006744Adobe Reader および Acrobat における境界外読み取りの脆弱性

Adobe Reader および Acrobat には、境界外読み取りの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006743Adobe Reader および Acrobat における境界外読み取りの脆弱性

Adobe Reader および Acrobat には、境界外読み取りの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006742Adobe Reader および Acrobat における境界外読み取りの脆弱性

Adobe Reader および Acrobat には、境界外読み取りの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006741Adobe Reader および Acrobat における境界外読み取りの脆弱性

Adobe Reader および Acrobat には、境界外読み取りの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006740Adobe Reader および Acrobat における境界外読み取りの脆弱性

Adobe Reader および Acrobat には、境界外読み取りの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006739Adobe Reader および Acrobat における境界外読み取りの脆弱性

Adobe Reader および Acrobat には、境界外読み取りの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006738Adobe Reader および Acrobat における境界外読み取りの脆弱性

Adobe Reader および Acrobat には、境界外読み取りの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006737Adobe Reader および Acrobat におけるメモリを破損される脆弱性

Adobe Reader および Acrobat には、メモリを破損される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006734Adobe Reader および Acrobat における境界外読み取りの脆弱性

Adobe Reader および Acrobat には、境界外読み取りの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006471Adobe Reader および Acrobat における二重解放の脆弱性

Adobe Reader および Acrobat には、二重解放の脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006771Adobe Reader および Acrobat におけるセキュリティを回避される脆弱性

Adobe Reader および Acrobat には、セキュリティを回避される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006769Adobe Reader および Acrobat における境界外読み取りの脆弱性

Adobe Reader および Acrobat には、境界外読み取りの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2018-006746Adobe Reader および Acrobat における境界外読み取りの脆弱性

Adobe Reader および Acrobat には、境界外読み取りの脆弱性が存在します。

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-4884Adobe 제품군 보안 업데이트 권고

- 임의 코드 실행으로 이어질 수 있는 Double Free 취약점(CVE-2018-4990)

Official advisory ↗
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Fix not verified
Affected
Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions: Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions
Fixed
No fixed version is explicitly recorded in the structured CVE data.
Action
No verified patch reference is present in the current structured sources. Check the vendor advisory before making a change.
Workaround
No verified workaround is recorded. If business-safe, reduce exposure to the affected interface and allow only trusted sources until authoritative guidance is available.
04

Evidence and provenance

Published 9 Jul 2018 · Last source change 21 Oct 2025, 23:45 UTC · CWE-415 · Double Free

CVE recordCVE.org · 5.1
CVSS sourceNIST NVD
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-09-01
European sourceENISA EUVD · EUVD-2018-16775
Product sourceCNA
Remediation sourceCVE/CNA references
CWE sourceCISA ADP
NVD statusNVD enriched

Core structured fields are present and their contributing authorities are shown above.

Material change intelligence

What changed after publication

View recent updates ↗
  1. Affected versionsThe structured affected or fixed version information changed.
    Before
    Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions · Fixed: No fixed version is explicitly recorded in the structured CVE data.
    After
    Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions: Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions · Fixed: No fixed version is explicitly recorded in the structured CVE data.
    CNA
  2. Vendor guidanceAuthoritative vendor guidance changed from no authoritative guidance recorded to vendor advisory.
    Before
    no authoritative guidance recorded
    After
    vendor advisory
    af854a3a-2127-422b-91ae-364da2661108
  3. CVSS scoreCVSS scoring authority changed from CISA ADP to NIST NVD; the displayed base score remained 8.8.
    Before
    8.8 (CVSS 3.1 · CISA ADP · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
    After
    8.8 (CVSS 3.1 · NIST NVD · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
    NIST NVD
  4. ENISA known-exploited stateENISA EUVD now records this CVE in its known-exploited dataset.
    Before
    not recorded
    After
    {"euvdId":"EUVD-2018-16775","listed":true,"sources":["cisa_kev"]}
    ENISA EUVD
  5. ENISA EUVD mappingEUVD-2018-16775 was added to the official ENISA EUVD mapping for this CVE.
    Before
    not recorded
    After
    {"euvdId":"EUVD-2018-16775"}
    ENISA EUVD
  6. Catalogue recordCVE added to the BlackTree catalogue.
    CNA
Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2018-4990 · cve.blacktree.nl