CVE-2018-4924
9.8
CRITICAL · CVSS 3.0 · EPSS 14% (pctl 96)
Patch early
EPSS 14% — above the 10% action threshold.
Description
Adobe Dreamweaver CC versions 18.0 and earlier have an OS Command Injection vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 14.01% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-05-19 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| adobe | dreamweaver |
| microsoft | windows |
References
- http://www.securityfocus.com/bid/103395
- http://www.securitytracker.com/id/1040516
- https://helpx.adobe.com/security/products/dreamweaver/apsb18-07.html
- http://www.securityfocus.com/bid/103395
- http://www.securitytracker.com/id/1040516
- https://helpx.adobe.com/security/products/dreamweaver/apsb18-07.html
→ the Explorer · watch your stack · NVD