Type Confusion Vulnerability in Adobe Acrobat and Reader
CVE-2017-16406
Key Information:
- Vendor
- Adobe
- Vendor
- CVE Published:
- 9 December 2017
Summary
A type confusion vulnerability exists in Adobe Acrobat and Reader due to improper handling in the EMF processing module. This flaw enables an attacker to manipulate the program to access objects with incompatible types, potentially resulting in out of bounds memory access. By exploiting this vulnerability, attackers may perform unintended reads, writes, or frees, which could lead to code corruption, control-flow hijacking, or unauthorized information disclosure.
Affected Version(s)
Adobe Acrobat Reader 2017.012.20098 and earlier , 2017.011.30066 and earlier , 2015.006.30355 and earlier , 11.0.22 and earlier Adobe Acrobat Reader 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, 11.0.22 and earlier versions
References
EPSS Score
7% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved