Buffer Overflow Vulnerability in Adobe Acrobat and Reader
CVE-2017-16407
Key Information:
- Vendor
Adobe
- Vendor
- CVE Published:
- 9 December 2017
What is CVE-2017-16407?
Adobe Acrobat and Reader versions prior to 2017.012.20098 are susceptible to a buffer overflow vulnerability caused by an improper calculation that writes data beyond the intended buffer limits. This issue lies within the handling of EMF EMR_BITBLT records and is driven by an out of range pointer offset used to access sub-elements of an internal data structure. Attackers can exploit this vulnerability to corrupt sensitive data or potentially execute arbitrary code, posing significant security risks to users.
Affected Version(s)
Adobe Acrobat Reader 2017.012.20098 and earlier , 2017.011.30066 and earlier , 2015.006.30355 and earlier , 11.0.22 and earlier Adobe Acrobat Reader 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, 11.0.22 and earlier versions
References
EPSS Score
14% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved