CVE-2018-4900
published 2018-02-27CVE-2018-4900: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions…
medium6.5CVSS 3.0
AVNACLPRNUIRSUCHINAN
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of JavaScript manipulation of an Annotation object. A successful attack can lead to sensitive data exposure.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | 17.0 – 17.011.30070 | — |
| adobe | acrobat_dc | - – 18.009.20050 | — |
| adobe | acrobat_dc | 15.0 – 15.006.30394 | — |
| adobe | acrobat_reader | 17.0 – 17.011.30070 | — |
| adobe | acrobat_reader_dc | - – 18.009.20050 | — |
| adobe | acrobat_reader_dc | 15.0 – 15.006.30394 | — |
No detection rules found.
No public exploits indexed.
Unit42
It’s Back! Don’t Panic, the Unit 42 Podcast, Returns with New Episodes
blogs_unit42·2018-02-22·CVSS 6.5
CVE-2018-4900 [MEDIUM] It’s Back! Don’t Panic, the Unit 42 Podcast, Returns with New Episodes
## It’s Back! Don’t Panic, the Unit 42 Podcast, Returns with New Episodes
Unit 42
Published: February 22, 2018
Threat Research
Vulnerabilities
Acrobat
Adobe
CVE-2018-4900
It’s time to “Don’t Panic” again!
Palo Alto Networks CSO Rick Howard and Palo Alto Networks Senior Director, Threat Intelligence Ryan Olson are back in the saddle with an all-new season of “Don’t Panic,” the official podcast of Unit 42, the Palo Alto Network threat intelligence team.
The first three episodes of the new season are posted and available for streaming via our Soundcloud page . In the next few weeks they will be available by additional streaming and downloading sources, too.
Give them a listen here:
You can find this episode and other Palo Alto Networks podcasts on iTunes , Google Play , or integr
Unit42
Unit 42 Vulnerability Research February 2018 Disclosures - Adobe
blogs_unit42·2018-02-13·CVSS 7.8
CVE-2018-4878 [HIGH] Unit 42 Vulnerability Research February 2018 Disclosures - Adobe
## Unit 42 Vulnerability Research February 2018 Disclosures - Adobe
Unit 42
Published: February 13, 2018
Malware
Threat Research
Vulnerabilities
Adobe
CVE-2018-4878
DogCall
As part of Unit 42’s ongoing threat research, we can now disclose that Palo Alto Networks Unit 42 researchers have discovered a vulnerability addressed by the Adobe Product Security Incident Response Team (PSIRT) as part of their February 2018 security update release .
CVE
Vulnerability Name
Affected Products
Maximum Severity Rating
Impact
Researcher(s)
CVE-2018-4900
Out-of-bounds read
Adobe Acrobat
Important
Remote Code Execution
Gal De Leon
Palo Alto Networks customers who deploy our Next-Generation Security Platform are protected from zero-day vulnerabilities such as these. Weaponized exploits
Unit42
Unit 42 Vulnerability Research February 2018 Disclosures - Adobe
blogs_unit42·2018-02-13·CVSS 6.5
CVE-2018-4900 [MEDIUM] Unit 42 Vulnerability Research February 2018 Disclosures - Adobe
As part of Unit 42’s ongoing threat research, we can now disclose that Palo Alto Networks Unit 42 researchers have discovered a vulnerability addressed by the Adobe Product Security Incident Response Team (PSIRT) as part of their February 2018 security update release.
CVE
Vulnerability Name
Affected Products
Maximum Severity Rating
Impact
Researcher(s)
CVE-2018-4900
Out-of-bounds read
Adobe Acrobat
Important
Remote Code Execution
Gal De Leon
Palo Alto Networks customers who deploy our Next-Generation Security Platform are protected from zero-day vulnerabilities such as these. Weaponized exploits for these vulnerabilities are prevented by Traps multi-layered exploit prevention capabilities. Threat prevention capabilities such as application control, IPS, and WildFire provide our customer
Zscaler
Zscaler protects against 22 new vulnerabilities for Adobe Fl
blogs_zscaler
Zscaler protects against 22 new vulnerabilities for Adobe Fl
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
2018-02-27
Published