Untrusted Pointer Dereference Vulnerability in Adobe Acrobat and Reader
CVE-2017-16372
Key Information:
- Vendor
- Adobe
- Vendor
- CVE Published:
- 9 December 2017
Summary
A vulnerability has been identified in Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, and 11.0.22 and earlier. This flaw arises from an untrusted pointer dereference in the JavaScript API engine. Specifically, an attacker can exploit this issue by crafting malicious JavaScript input that leads to dereferencing pointers pointing to memory locations outside the intended process address space. This exploitation can involve a read operation that potentially discloses sensitive information stored in memory.
Affected Version(s)
Adobe Acrobat Reader 2017.012.20098 and earlier , 2017.011.30066 and earlier , 2015.006.30355 and earlier , 11.0.22 and earlier Adobe Acrobat Reader 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, 11.0.22 and earlier versions
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved