Think you have a false positive on this rule?

Sid 1-48134

Message

FILE-IMAGE Adobe Acrobat SGI parsing out of bounds read attempt

Summary

This event is generated when an SGI file that exploits the vulnerability outlined in CVE-2018-15953 is detected.

Impact

Out of bounds read, information disclosure

CVE-2018-15953:

CVSS base score 5.5

CVSS impact score 3.6

CVSS exploitability score 1.8

Confidentiality Impact HIGH

Integrity Impact NONE

Availability Impact NONE

Detailed information

CVE-2018-15953: Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

Affected systems

  • adobe acrobat 17.011.30059
  • adobe acrobat 17.011.30065
  • adobe acrobat 17.011.30068
  • adobe acrobat 17.011.30070
  • adobe acrobat 17.011.30096
  • adobe acrobat 17.011.30102
  • adobe acrobat_dc 15.006.30060
  • adobe acrobat_dc 15.006.30094
  • adobe acrobat_dc 15.006.30096
  • adobe acrobat_dc 15.006.30097
  • adobe acrobat_dc 15.006.30119
  • adobe acrobat_dc 15.006.30121
  • adobe acrobat_dc 15.006.30172
  • adobe acrobat_dc 15.006.30173
  • adobe acrobat_dc 15.006.30174
  • adobe acrobat_dc 15.006.30198
  • adobe acrobat_dc 15.006.30201
  • adobe acrobat_dc 15.006.30243
  • adobe acrobat_dc 15.006.30244
  • adobe acrobat_dc 15.006.30279
  • adobe acrobat_dc 15.006.30280
  • adobe acrobat_dc 15.006.30306
  • adobe acrobat_dc 15.006.30352
  • adobe acrobat_dc 15.006.30354
  • adobe acrobat_dc 15.006.30355
  • adobe acrobat_dc 15.006.30392
  • adobe acrobat_dc 15.006.30394
  • adobe acrobat_dc 15.006.30434
  • adobe acrobat_dc 15.006.30452
  • adobe acrobat_dc 15.008.20082
  • adobe acrobat_dc 15.009.20069
  • adobe acrobat_dc 15.009.20071
  • adobe acrobat_dc 15.009.20077
  • adobe acrobat_dc 15.009.20079
  • adobe acrobat_dc 15.010.20056
  • adobe acrobat_dc 15.010.20059
  • adobe acrobat_dc 15.010.20060
  • adobe acrobat_dc 15.016.20039
  • adobe acrobat_dc 15.016.20041
  • adobe acrobat_dc 15.016.20045
  • adobe acrobat_dc 15.017.20050
  • adobe acrobat_dc 15.017.20053
  • adobe acrobat_dc 15.020.20039
  • adobe acrobat_dc 15.020.20042
  • adobe acrobat_dc 15.023.20053
  • adobe acrobat_dc 15.023.20056
  • adobe acrobat_dc 15.023.20070
  • adobe acrobat_dc 17.009.20044
  • adobe acrobat_dc 17.009.20058
  • adobe acrobat_dc 17.012.20093
  • adobe acrobat_dc 17.012.20095
  • adobe acrobat_dc 17.012.20096
  • adobe acrobat_dc 17.012.20098
  • adobe acrobat_dc 18.009.20044
  • adobe acrobat_dc 18.009.20050
  • adobe acrobat_dc 18.011.20055
  • adobe acrobat_dc 18.011.20063
  • adobe acrobat_reader 17.011.30059
  • adobe acrobat_reader 17.011.30096
  • adobe acrobat_reader 17.011.30102
  • adobe acrobatreaderdc 15.006.30060
  • adobe acrobatreaderdc 15.006.30094
  • adobe acrobatreaderdc 15.006.30096
  • adobe acrobatreaderdc 15.006.30097
  • adobe acrobatreaderdc 15.006.30119
  • adobe acrobatreaderdc 15.006.30121
  • adobe acrobatreaderdc 15.006.30172
  • adobe acrobatreaderdc 15.006.30173
  • adobe acrobatreaderdc 15.006.30174
  • adobe acrobatreaderdc 15.006.30198
  • adobe acrobatreaderdc 15.006.30201
  • adobe acrobatreaderdc 15.006.30243
  • adobe acrobatreaderdc 15.006.30244
  • adobe acrobatreaderdc 15.006.30279
  • adobe acrobatreaderdc 15.006.30280
  • adobe acrobatreaderdc 15.006.30306
  • adobe acrobatreaderdc 15.006.30352
  • adobe acrobatreaderdc 15.006.30354
  • adobe acrobatreaderdc 15.006.30355
  • adobe acrobatreaderdc 15.006.30392
  • adobe acrobatreaderdc 15.006.30394
  • adobe acrobatreaderdc 15.006.30434
  • adobe acrobatreaderdc 15.006.30452
  • adobe acrobatreaderdc 15.008.20082
  • adobe acrobatreaderdc 15.009.20069
  • adobe acrobatreaderdc 15.009.20071
  • adobe acrobatreaderdc 15.009.20077
  • adobe acrobatreaderdc 15.009.20079
  • adobe acrobatreaderdc 15.010.20056
  • adobe acrobatreaderdc 15.010.20059
  • adobe acrobatreaderdc 15.010.20060
  • adobe acrobatreaderdc 15.016.20039
  • adobe acrobatreaderdc 15.016.20041
  • adobe acrobatreaderdc 15.016.20045
  • adobe acrobatreaderdc 15.017.20050
  • adobe acrobatreaderdc 15.017.20053
  • adobe acrobatreaderdc 15.020.20039
  • adobe acrobatreaderdc 15.020.20042
  • adobe acrobatreaderdc 15.023.20053
  • adobe acrobatreaderdc 15.023.20056
  • adobe acrobatreaderdc 15.023.20070
  • adobe acrobatreaderdc 17.009.20044
  • adobe acrobatreaderdc 17.009.20058
  • adobe acrobatreaderdc 17.012.20093
  • adobe acrobatreaderdc 17.012.20095
  • adobe acrobatreaderdc 17.012.20098
  • adobe acrobatreaderdc 18.009.20044
  • adobe acrobatreaderdc 18.009.20050
  • adobe acrobatreaderdc 18.011.20055
  • adobe acrobatreaderdc 18.011.20063

Ease of attack

CVE-2018-15953:

Access Vector

Access Complexity

Authentication

False positives

False negatives

Corrective action

Contributors

  • Cisco's Talos Intelligence Group

Additional References

  • helpx.adobe.com/security/products/acrobat/APSB18-30.html