CVE-2016-6949: Use After Free
Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1089, CVE-2016-1091, CVE-2016-6944, CVE-2016-6945, CVE-2016-6946, CVE-2016-6952, CVE-2016-6953, CVE-2016-6961, CVE-2016-6962, CVE-2016-6963, CVE-2016-6964, CVE-2016-6965, CVE-2016-6967, CVE-2016-6968, CVE-2016-6969, CVE-2016-6971, CVE-2016-6979, CVE-2016-6988, and CVE-2016-6993.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6949?
CVE-2016-6949 is rated as critical due to its potential to allow attackers to execute arbitrary code.
How do I fix CVE-2016-6949?
To address CVE-2016-6949, upgrade Adobe Reader and Acrobat to versions 11.0.18 or later, and 15.006.30243 or later for DC Classic and 15.020.20039 or later for Continuous.
What software is affected by CVE-2016-6949?
CVE-2016-6949 affects Adobe Reader and Acrobat versions prior to 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039.
What types of attacks can exploit CVE-2016-6949?
CVE-2016-6949 can be exploited to perform arbitrary code execution, potentially compromising the user's system.
Is there a workaround for CVE-2016-6949?
There are no official workarounds for CVE-2016-6949; updating to a patched version is recommended to mitigate the vulnerability.