Netskope Threat Labs

FILE-OTHER Adobe Acrobat Pro malformed EMF EmfPlustDrawImagePoints out of bounds read attempt

IPS-SWG

1 SID: 45663

First seen
January 2024
Last seen
October 2026

Detects a document exploiting CVE-2018-4906, an out-of-bounds read in Adobe Acrobat's metafile image handling that can leak memory. The rule matches the malformed draw image records that public exploits use to read beyond allocated buffers.