CVE-2016-6999
CRITICALAdobe Acrobat/Reader <11.0.18, Acrobat DC <15.006.30243, Acrobat Reader DC <15.020.20039 RCE via Integer Overflow
Title source: llmDescription
Integer overflow in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/93495
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1036986
Patch, Vendor Advisory x_refsource_confirm
https://helpx.adobe.com/security/products/acrobat/apsb16-33.html
Scores
CVSS v3
9.8
EPSS
0.0575
EPSS Percentile
92.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-190
Status
published
Products (6)
adobe/acrobat
< 11.0.17
adobe/acrobat_dc
< 15.006.30201
adobe/acrobat_dc
< 15.017.20053
adobe/acrobat_reader_dc
< 15.006.30201
adobe/acrobat_reader_dc
< 15.017.20053
adobe/reader
< 11.0.17
Published
Oct 13, 2016
Tracked Since
Feb 18, 2026