Netskope Threat Labs

FILE-IMAGE Adobe Acrobat EmfPlusDrawImagePoints out of bounds read attempt

IPS-SWG

1 SID: 47827

First seen
January 2025
Last seen
September 2026

Detects a PDF exploiting CVE-2018-5035, an out-of-bounds read in Adobe Acrobat's enhanced metafile image handling that can leak memory. The rule matches the crafted draw image records that public exploits use to read beyond allocated buffers.