CVE-2017-16364

HIGH

Adobe Acrobat and Reader <2017.012.20098 - Memory Corruption

Title source: llm
STIX 2.1

Description

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This issue is due to an untrusted pointer dereference when handling number format dictionary entries. In this scenario, the input is crafted in way that the computation results in pointers to memory locations that do not belong to the relevant process address space. The dereferencing operation is a read operation, and an attack can result in sensitive data exposure.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1039791
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/101813

Scores

CVSS v3 8.8
EPSS 0.0672
EPSS Percentile 93.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (7)
adobe/acrobat < 11.0.22
adobe/acrobat_dc - - 17.012.20098
adobe/acrobat_dc 15.0 - 15.006.30355
adobe/acrobat_reader < 11.0.22
adobe/acrobat_reader_dc - - 17.012.20098
adobe/acrobat_reader_dc 15.0 - 15.006.30355
n/a/Adobe Acrobat Reader 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, 11.0.22 and earlier versions Adobe Acrobat Reader 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.
Published Dec 09, 2017
Tracked Since Feb 18, 2026