Think you have a false positive on this rule?

Sid 1-46660

Message

FILE-OTHER Adobe Acrobat Reader jp2 double free attempt

Summary

This event is generated when an attempt to exploit a double free in Adobe Acrobat Reader is detected.

Impact

Attempted User Privilege Gain

CVE-2018-4990:

CVSS base score 8.8

CVSS impact score 5.9

CVSS exploitability score 2.8

Confidentiality Impact HIGH

Integrity Impact HIGH

Availability Impact HIGH

Detailed information

CVE-2018-4990: Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Affected systems

  • adobe acrobat 17.011.30059
  • adobe acrobat 17.011.30065
  • adobe acrobat 17.011.30068
  • adobe acrobat 17.011.30070
  • adobe acrobat_dc 15.006.30060
  • adobe acrobat_dc 15.006.30094
  • adobe acrobat_dc 15.006.30096
  • adobe acrobat_dc 15.006.30097
  • adobe acrobat_dc 15.006.30119
  • adobe acrobat_dc 15.006.30121
  • adobe acrobat_dc 15.006.30172
  • adobe acrobat_dc 15.006.30173
  • adobe acrobat_dc 15.006.30174
  • adobe acrobat_dc 15.006.30198
  • adobe acrobat_dc 15.006.30201
  • adobe acrobat_dc 15.006.30243
  • adobe acrobat_dc 15.006.30244
  • adobe acrobat_dc 15.006.30279
  • adobe acrobat_dc 15.006.30280
  • adobe acrobat_dc 15.006.30306
  • adobe acrobat_dc 15.006.30352
  • adobe acrobat_dc 15.006.30354
  • adobe acrobat_dc 15.006.30355
  • adobe acrobat_dc 15.006.30392
  • adobe acrobat_dc 15.006.30394
  • adobe acrobat_dc 15.008.20082
  • adobe acrobat_dc 15.009.20069
  • adobe acrobat_dc 15.009.20071
  • adobe acrobat_dc 15.009.20077
  • adobe acrobat_dc 15.009.20079
  • adobe acrobat_dc 15.010.20056
  • adobe acrobat_dc 15.010.20059
  • adobe acrobat_dc 15.010.20060
  • adobe acrobat_dc 15.016.20039
  • adobe acrobat_dc 15.016.20041
  • adobe acrobat_dc 15.016.20045
  • adobe acrobat_dc 15.017.20050
  • adobe acrobat_dc 15.017.20053
  • adobe acrobat_dc 15.020.20039
  • adobe acrobat_dc 15.020.20042
  • adobe acrobat_dc 15.023.20053
  • adobe acrobat_dc 15.023.20056
  • adobe acrobat_dc 15.023.20070
  • adobe acrobat_dc 17.009.20044
  • adobe acrobat_dc 17.009.20058
  • adobe acrobat_dc 17.012.20093
  • adobe acrobat_dc 17.012.20095
  • adobe acrobat_dc 17.012.20096
  • adobe acrobat_dc 17.012.20098
  • adobe acrobat_dc 18.009.20044
  • adobe acrobat_dc 18.009.20050
  • adobe acrobat_reader 17.011.30059
  • adobe acrobatreaderdc 15.006.30060
  • adobe acrobatreaderdc 15.006.30094
  • adobe acrobatreaderdc 15.006.30096
  • adobe acrobatreaderdc 15.006.30097
  • adobe acrobatreaderdc 15.006.30119
  • adobe acrobatreaderdc 15.006.30121
  • adobe acrobatreaderdc 15.006.30172
  • adobe acrobatreaderdc 15.006.30173
  • adobe acrobatreaderdc 15.006.30174
  • adobe acrobatreaderdc 15.006.30198
  • adobe acrobatreaderdc 15.006.30201
  • adobe acrobatreaderdc 15.006.30243
  • adobe acrobatreaderdc 15.006.30244
  • adobe acrobatreaderdc 15.006.30279
  • adobe acrobatreaderdc 15.006.30280
  • adobe acrobatreaderdc 15.006.30306
  • adobe acrobatreaderdc 15.006.30352
  • adobe acrobatreaderdc 15.006.30354
  • adobe acrobatreaderdc 15.006.30355
  • adobe acrobatreaderdc 15.006.30392
  • adobe acrobatreaderdc 15.006.30394
  • adobe acrobatreaderdc 15.008.20082
  • adobe acrobatreaderdc 15.009.20069
  • adobe acrobatreaderdc 15.009.20071
  • adobe acrobatreaderdc 15.009.20077
  • adobe acrobatreaderdc 15.009.20079
  • adobe acrobatreaderdc 15.010.20056
  • adobe acrobatreaderdc 15.010.20059
  • adobe acrobatreaderdc 15.010.20060
  • adobe acrobatreaderdc 15.016.20039
  • adobe acrobatreaderdc 15.016.20041
  • adobe acrobatreaderdc 15.016.20045
  • adobe acrobatreaderdc 15.017.20050
  • adobe acrobatreaderdc 15.017.20053
  • adobe acrobatreaderdc 15.020.20039
  • adobe acrobatreaderdc 15.020.20042
  • adobe acrobatreaderdc 15.023.20053
  • adobe acrobatreaderdc 15.023.20056
  • adobe acrobatreaderdc 15.023.20070
  • adobe acrobatreaderdc 17.009.20044
  • adobe acrobatreaderdc 17.009.20058
  • adobe acrobatreaderdc 17.012.20093
  • adobe acrobatreaderdc 17.012.20095
  • adobe acrobatreaderdc 17.012.20098
  • adobe acrobatreaderdc 18.009.20044
  • adobe acrobatreaderdc 18.009.20050

Ease of attack

CVE-2018-4990:

Access Vector

Access Complexity

Authentication

False positives

False negatives

Corrective action

Contributors

  • Cisco's Talos Intelligence Group

Additional References

  • helpx.adobe.com/security/products/acrobat/APSB18-09.html