CVE-2018-15979

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
29/11/2018
Last modified:
21/08/2019

Description

Adobe Acrobat and Reader versions 2019.008.20080 and earlier, 2017.011.30105 and earlier, and 2015.006.30456 and earlier have a ntlm sso hash theft vulnerability. Successful exploitation could lead to information disclosure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* 15.006.30060 (including) 15.006.30456 (including)
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* 15.008.20082 (including) 19.008.20080 (including)
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* 17.011.30059 (including) 17.011.30105 (including)
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* 15.006.30060 (including) 15.006.30456 (including)
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* 15.008.20082 (including) 19.008.20080 (including)
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* 17.011.30059 (including) 17.011.30105 (including)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*