CVE-2017-16372: Buffer Overflow
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This issue is due to untrusted pointer dereference in the JavaScript API engine. In this scenario, the JavaScript input is crafted in way that the computation results with pointer to memory locations that do not belong to the relevant process address space. The dereferencing operation is a read operation, and an attack can result with sensitive data exposure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16372?
The severity of CVE-2017-16372 is classified as critical due to the potential for remote code execution.
How do I fix CVE-2017-16372?
To fix CVE-2017-16372, update Adobe Acrobat and Reader to the latest version provided by Adobe.
Which versions of Adobe Acrobat are affected by CVE-2017-16372?
CVE-2017-16372 affects Adobe Acrobat and Reader versions 11.0.22 and earlier, all 2015 versions, and versions 17.0 through 17.012.20098.
What is the impact of CVE-2017-16372?
The impact of CVE-2017-16372 includes possible exploitation via untrusted pointer dereference, which may lead to arbitrary code execution.
Is CVE-2017-16372 a vulnerability in Adobe Acrobat Reader or Acrobat DC?
CVE-2017-16372 is a vulnerability present in both Adobe Acrobat Reader and Acrobat DC, specifically in the affected versions mentioned.