CVE-2018-4993

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
09/07/2018
Last modified:
21/08/2019

Description

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO hash theft vulnerability. Successful exploitation could lead to information disclosure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* 15.006.30060 (including) 15.006.30417 (including)
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* 15.008.20082 (including) 18.011.20038 (including)
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* 17.011.30059 (including) 17.011.30079 (including)
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* 15.006.30060 (including) 15.006.30417 (including)
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* 15.008.20082 (including) 18.011.20038 (including)
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* 17.011.30059 (including) 17.011.30079 (including)
cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*