Buffer Overflow Vulnerability in Adobe Acrobat and Reader
CVE-2017-16401
Key Information:
- Vendor
- Adobe
- Vendor
- CVE Published:
- 9 December 2017
Summary
A vulnerability has been identified in Adobe Acrobat and Reader due to improper handling of pointers during image conversion processes, specifically when processing Enhanced Metafile Format Plus (EMF +) images. An attacker could exploit this weakness by providing crafted EMF + content that triggers a computation to read beyond the intended buffer limits. This out-of-range pointer access can lead to the exposure of sensitive data stored in memory, posing a threat to user information and system integrity.
Affected Version(s)
Adobe Acrobat Reader 2017.012.20098 and earlier , 2017.011.30066 and earlier , 2015.006.30355 and earlier , 11.0.22 and earlier Adobe Acrobat Reader 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, 11.0.22 and earlier versions
References
EPSS Score
12% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved