peter bassill · operator
$ cve CVE-2018-4924 JSON

CVE-2018-4924

9.8
CRITICAL · CVSS 3.0 · EPSS 14% (pctl 96)

Patch early

EPSS 14% — above the 10% action threshold.

Description

Adobe Dreamweaver CC versions 18.0 and earlier have an OS Command Injection vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS14.01% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2018-05-19
Last modified2026-06-17

Affected (2)

VendorProduct
adobedreamweaver
microsoftwindows

References

→ the Explorer  ·  watch your stack  ·  NVD