CVE-2018-4917: Adobe Acrobat 2017

Critical severity, CVSS 9.8. EPSS: 17.3% chance of exploitation in the next 30 days.

Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, 2015.006.30394 and earlier have an exploitable heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Affected products

  • Adobe Acrobat 2017: from 17.011.30070, before 17.011.30078 (fixed in 17.011.30078)
  • Adobe Acrobat DC: from 15.006.30394, before 15.006.30413 (fixed in 15.006.30413); from 18.009.20050, before 18.011.20035 (fixed in 18.011.20035)
  • Adobe Acrobat Reader 2017: from 17.011.30070, before 17.011.30078 (fixed in 17.011.30078)
  • Adobe Acrobat Reader DC: from 15.006.30394, before 15.006.30413 (fixed in 15.006.30413); from 18.009.20050, before 18.011.20035 (fixed in 18.011.20035)

Published 2018-05-19. Last modified 2026-06-17.