vciy

Adobe Acrobat and Reader: 46 records in one advisory

46 records announced together, published 2018-07-09, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://helpx.adobe.com/security/products/acrobat/apsb18-09.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

1 record is listed by CISA with a required action, which carries a federal remediation deadline on its own page.

6 of 46 records name something of its own. For the other 40, held sources say the same thing about each.

Most commonly mapped weakness across the batch: Out-of-bounds read.

What this page does not cover

This batch is 46 of the 48 records that cite the same advisory. The other 2 are different findings announced alongside it.

None of those 2 is grouped with any other. Each one has its own record page and nothing else.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

Most of this May 2018 Reader batch came from researchers; one came out of a live attack

Adobe published this bulletin for Acrobat and Reader on 14 May 2018. One entry in it did not come from anyone hunting bugs. CVE-2018-4990 was found by Anton Cherepanov of ESET and Matt Oh of Microsoft while they were examining a malicious PDF file pulled from a public malware repository. The sample chained a Reader flaw to a Windows privilege escalation flaw, CVE-2018-8120, so that opening the document was enough to take the machine. Microsoft published the analysis on 2 July 2018. Adobe's bulletin records that an exploit for CVE-2018-4990 existed in the wild, and the United States cyber defence agency added that identifier on 8 June 2022 to its catalogue of vulnerabilities known to have been exploited. Nothing comparable is on record for any other identifier in this group.

One of these, CVE-2018-4990, turned up in a real attack before there was a fix. Sharing a bulletin with it tells you nothing about whether any other record here was ever used against anybody.

2018-05-14Adobe publishes the Acrobat and Reader bulletin.
2018-05-15Adobe revises the bulletin to record that an exploit for CVE-2018-4990 exists in the wild.
2018-07-02Microsoft publishes its analysis of the malicious PDF sample found with ESET, which chained CVE-2018-4990 to CVE-2018-8120.
2022-06-08The United States cyber defence agency adds CVE-2018-4990 to its catalogue of vulnerabilities known to have been exploited.

Adobe gives a flaw class and an impact for each identifier and no technical detail, so nothing says which file feature or code path is involved in any one of them. The dates do not line up either: Adobe's bulletin is dated 14 May 2018 while the records in this group carry a publication date of 9 July 2018, and no source we can link explains the gap.

Written from helpx.adobe.com, microsoft.com, securityweek.com, cisa.gov. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2018-4947no title heldHeap Overflow
CVE-2018-4948no title heldHeap Overflow
CVE-2018-4949no title heldOut-of-bounds read
CVE-2018-4950writeOut-of-bounds write
CVE-2018-4951no title heldOut-of-bounds read
CVE-2018-4952no title heldUse-after-free
CVE-2018-4953no title heldType Confusion
CVE-2018-4954no title heldUse-after-free
CVE-2018-4955no title heldOut-of-bounds read
CVE-2018-4956no title heldOut-of-bounds read
CVE-2018-4957no title heldOut-of-bounds read
CVE-2018-4958no title heldUse-after-free
CVE-2018-4959no title heldUse-after-free
CVE-2018-4960no title heldOut-of-bounds read
CVE-2018-4961no title heldUse-after-free
CVE-2018-4962no title heldOut-of-bounds read
CVE-2018-4963no title heldOut-of-bounds read
CVE-2018-4964no title heldOut-of-bounds read
CVE-2018-4965memory corruptionMemory Corruption
CVE-2018-4966no title heldHeap Overflow
CVE-2018-4967no title heldOut-of-bounds read
CVE-2018-4968no title heldHeap Overflow
CVE-2018-4969no title heldOut-of-bounds read
CVE-2018-4970no title heldOut-of-bounds read
CVE-2018-4971no title heldUse-after-free
CVE-2018-4972no title heldOut-of-bounds read
CVE-2018-4973no title heldOut-of-bounds read
CVE-2018-4974no title heldUse-after-free
CVE-2018-4975no title heldOut-of-bounds read
CVE-2018-4976no title heldOut-of-bounds read
CVE-2018-4977no title heldUse-after-free
CVE-2018-4978no title heldHeap Overflow
CVE-2018-4979no title heldSecurity Bypass
CVE-2018-4980no title heldUse-after-free
CVE-2018-4981no title heldOut-of-bounds read
CVE-2018-4982no title heldHeap Overflow
CVE-2018-4983no title heldUse-after-free
CVE-2018-4984no title heldHeap Overflow
CVE-2018-4986no title heldOut-of-bounds read
CVE-2018-4987untrusted pointer dereferenceUntrusted pointer dereference
CVE-2018-4988no title heldUse-after-free
CVE-2018-4989no title heldUse-after-free
CVE-2018-4990double freeDouble Free
CVE-2018-4993ntlm sso hash theftNTLM SSO hash theft
CVE-2018-4995xfa post injectionXFA '\n' POST injection
CVE-2018-4996no title heldUse-after-free

46 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.