CVE-2017-16380: Critical severity adobe acrobat reader vulnerability
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a security bypass vulnerability for a certain file-type extension. Acrobat maintains both a blacklist and whitelist (the user can specify an allowed attachment). However, any file extensions that are neither on the blacklist nor the whitelist can still be opened after displaying a warning prompt.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16380?
CVE-2017-16380 is classified as a security bypass vulnerability in Adobe Acrobat and Reader.
How do I fix CVE-2017-16380?
To fix CVE-2017-16380, update Adobe Acrobat and Reader to the latest versions that address this vulnerability.
Which versions are affected by CVE-2017-16380?
CVE-2017-16380 affects Adobe Acrobat and Reader versions up to 11.0.22, 2015.006.30355, 2017.011.30066, and 2017.012.20098 and earlier.
What types of products are impacted by CVE-2017-16380?
CVE-2017-16380 impacts Adobe Acrobat, Adobe Reader, and Adobe Acrobat DC in various versions.
Can CVE-2017-16380 lead to further exploitation?
Yes, CVE-2017-16380's security bypass could potentially allow attackers to perform additional actions or gain unauthorized access.