Out-of-Bounds Read Vulnerability in Adobe Acrobat and Reader Products
CVE-2017-16412
Key Information:
- Vendor
- Adobe
- Vendor
- CVE Published:
- 9 December 2017
Summary
An out-of-bounds read vulnerability exists in Adobe Acrobat and Reader that stems from improper handling of JPEG resources during XPS conversion. Specifically, this issue is triggered by the use of an invalid pointer offset while accessing internal data structures, allowing attackers to read sensitive data beyond the allocated buffer. This vulnerability affects multiple versions of the software, including Adobe Acrobat 2017 and earlier, potentially exposing users to risks of data leakage.
Affected Version(s)
Adobe Acrobat Reader 2017.012.20098 and earlier , 2017.011.30066 and earlier , 2015.006.30355 and earlier , 11.0.22 and earlier Adobe Acrobat Reader 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, 11.0.22 and earlier versions
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved