Vulnerability Details : CVE-2018-16037
Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
Vulnerability category: Memory Corruption
Exploit prediction scoring system (EPSS) score for CVE-2018-16037
Probability of exploitation activity in the next 30 days: 0.43%
Percentile, the proportion of vulnerabilities that are scored at or less: ~ 71 % EPSS Score History EPSS FAQ
CVSS scores for CVE-2018-16037
Base Score | Base Severity | CVSS Vector | Exploitability Score | Impact Score | Score Source |
---|---|---|---|---|---|
10.0
|
HIGH | AV:N/AC:L/Au:N/C:C/I:C/A:C |
10.0
|
10.0
|
NIST |
9.8
|
CRITICAL | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
3.9
|
5.9
|
NIST |
CWE ids for CVE-2018-16037
-
Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.Assigned by: nvd@nist.gov (Primary)
References for CVE-2018-16037
-
https://helpx.adobe.com/security/products/acrobat/apsb18-41.html
Adobe Security BulletinPatch;Vendor Advisory
-
http://www.securityfocus.com/bid/106164
Adobe Acrobat and Reader APSB18-41 Multiple Arbitrary Code Execution VulnerabilitiesThird Party Advisory;VDB Entry
Products affected by CVE-2018-16037
- Adobe » Acrobat Dc » Classic EditionVersions from including (>=) 17.011.30056 and up to, including, (<=) 17.011.30106cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:*
- Adobe » Acrobat Dc » Continuous EditionVersions from including (>=) 15.008.20082 and up to, including, (<=) 19.008.20081cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
- Adobe » Acrobat Dc » Classic EditionVersions from including (>=) 15.006.30060 and up to, including, (<=) 15.006.30456cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:*
- Adobe » Acrobat Dc » Continuous EditionVersions from including (>=) 15.008.20082 and up to, including, (<=) 19.008.20080cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
- Adobe » Acrobat Dc » Classic EditionVersions from including (>=) 17.011.30056 and up to, including, (<=) 17.011.30105cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:*
- Adobe » Acrobat Dc » Classic EditionVersions from including (>=) 15.006.30060 and up to, including, (<=) 15.006.30457cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:*
- Adobe » Acrobat Reader Dc » Classic EditionVersions from including (>=) 15.006.30060 and up to, including, (<=) 15.006.30457cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:*
- Adobe » Acrobat Reader Dc » Continuous EditionVersions from including (>=) 15.008.20082 and up to, including, (<=) 19.008.20080cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
- Adobe » Acrobat Reader Dc » Continuous EditionVersions from including (>=) 15.008.20082 and up to, including, (<=) 19.008.20081cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
- Adobe » Acrobat Reader Dc » Classic EditionVersions from including (>=) 15.006.30060 and up to, including, (<=) 15.006.30456cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:*
- Adobe » Acrobat Reader Dc » Classic EditionVersions from including (>=) 17.011.30059 and up to, including, (<=) 17.011.30105cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:*
- Adobe » Acrobat Reader Dc » Classic EditionVersions from including (>=) 17.011.30059 and up to, including, (<=) 17.011.30106cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:*