Netskope Threat Labs

FILE-PDF Adobe Acrobat Reader go-to action NTLM credential disclosure attempt

IPS-SWG

1 SID: 46676

First seen
September 2022
Last seen
October 2026

Detects a PDF exploiting CVE-2018-4993, the remote action flaw that makes Adobe Acrobat Reader authenticate to an operator-controlled host and leak hashed credentials. The rule matches the remote document action references carrying network paths.