First published: Wed Jul 13 2016(Updated: )
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4191, CVE-2016-4192, CVE-2016-4193, CVE-2016-4194, CVE-2016-4195, CVE-2016-4196, CVE-2016-4197, CVE-2016-4199, CVE-2016-4200, CVE-2016-4201, CVE-2016-4202, CVE-2016-4203, CVE-2016-4204, CVE-2016-4205, CVE-2016-4206, CVE-2016-4207, CVE-2016-4208, CVE-2016-4211, CVE-2016-4212, CVE-2016-4213, CVE-2016-4214, CVE-2016-4250, CVE-2016-4251, CVE-2016-4252, and CVE-2016-4254.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | ||
Microsoft Windows | ||
Adobe Acrobat Reader | <=11.0.16 | |
Adobe Acrobat | <=15.006.30174 | |
Adobe Acrobat | <=15.016.20045 | |
Adobe Acrobat Reader | <=15.006.30174 | |
Adobe Acrobat Reader | <=15.016.20045 | |
Adobe Acrobat Reader | <=11.0.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4198 is classified as a critical severity vulnerability due to its potential to allow arbitrary code execution.
To fix CVE-2016-4198, ensure that your Adobe Reader or Acrobat software is updated to version 11.0.17 or later for Adobe Acrobat and version 15.017.20050 or later for Acrobat DC.
CVE-2016-4198 affects Adobe Reader and Acrobat versions prior to 11.0.17 and 15.006.30198, as well as related Acrobat DC versions before 15.017.20050.
Yes, CVE-2016-4198 can potentially cause a denial of service as it involves memory corruption issues.
CVE-2016-4198 impacts Adobe Reader and Acrobat on both Windows and OS X platforms.