CVE-2016-6938: Use After Free
Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4255.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6938?
CVE-2016-6938 is rated as critical due to its ability to allow remote code execution.
How do I fix CVE-2016-6938?
To fix CVE-2016-6938, update Adobe Reader and Acrobat to versions 11.0.17 or later, and for Acrobat DC Classic to 15.006.30198 or later.
Which versions of Adobe software are affected by CVE-2016-6938?
CVE-2016-6938 affects Adobe Reader and Acrobat versions prior to 11.0.17, Acrobat DC Classic prior to 15.006.30198, and Acrobat DC Continuous prior to 15.017.20050.
Can CVE-2016-6938 be exploited remotely?
Yes, CVE-2016-6938 can be exploited remotely, allowing attackers to execute arbitrary code on the affected systems.
What platforms are impacted by CVE-2016-6938?
CVE-2016-6938 affects both Windows and macOS platforms running vulnerable versions of Adobe Reader and Acrobat.