CVE-2016-6988: Use After Free
Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1089, CVE-2016-1091, CVE-2016-6944, CVE-2016-6945, CVE-2016-6946, CVE-2016-6949, CVE-2016-6952, CVE-2016-6953, CVE-2016-6961, CVE-2016-6962, CVE-2016-6963, CVE-2016-6964, CVE-2016-6965, CVE-2016-6967, CVE-2016-6968, CVE-2016-6969, CVE-2016-6971, CVE-2016-6979, and CVE-2016-6993.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6988?
CVE-2016-6988 has a critical severity rating due to its potential to allow attackers to execute arbitrary code.
How do I fix CVE-2016-6988?
To fix CVE-2016-6988, upgrade Adobe Reader and Acrobat to versions 11.0.18 or later, or Adobe Acrobat and Acrobat Reader DC to versions 15.006.30243 or later.
Which Adobe products are affected by CVE-2016-6988?
CVE-2016-6988 affects Adobe Acrobat Reader version 11.0.17 and earlier, and various versions of Adobe Acrobat DC prior to 15.006.30243.
What platforms are vulnerable to CVE-2016-6988?
CVE-2016-6988 impacts users on both Windows and macOS platforms.
Can CVE-2016-6988 be exploited remotely?
Yes, CVE-2016-6988 can be exploited remotely through unspecified vectors, allowing an attacker to run malicious code.