CVE-2017-16384: Critical severity adobe acrobat reader vulnerability
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer over-read in the exif processing module for a PNG file (during XPS conversion). Invalid input leads to a computation where pointer arithmetic results in a location outside valid memory locations belonging to the buffer. An attack can be used to obtain sensitive information, such as object heap addresses, etc.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16384?
CVE-2017-16384 has a critical severity level due to potential remote code execution risks.
How do I fix CVE-2017-16384?
To fix CVE-2017-16384, update Adobe Acrobat and Reader to the latest versions available.
What versions of Adobe Acrobat and Reader are affected by CVE-2017-16384?
CVE-2017-16384 affects Adobe Acrobat and Reader versions prior to 2017.012.20098, 2017.011.30066, 2015.006.30355, and 11.0.22.
Can CVE-2017-16384 be exploited through a malicious PNG file?
Yes, CVE-2017-16384 can be exploited by processing a specially crafted PNG file.
What type of vulnerability is CVE-2017-16384?
CVE-2017-16384 is a buffer over-read vulnerability in the exif processing module.