CVE-2017-16388: Use After Free
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the JavaScript API engine. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption, control-flow hijack, or an information leak attack. Successful exploitation could lead to arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16388?
CVE-2017-16388 is considered to have a critical severity level due to the potential for remote code execution.
How do I fix CVE-2017-16388?
To fix CVE-2017-16388, upgrade Adobe Acrobat and Reader to the latest version as provided in security updates.
What types of software are affected by CVE-2017-16388?
CVE-2017-16388 affects various versions of Adobe Acrobat and Adobe Acrobat Reader prior to specified versions.
What is a use after free vulnerability as seen in CVE-2017-16388?
A use after free vulnerability occurs when a program continues to use a pointer after the memory it points to has been freed, potentially leading to crashes or code execution.
What are the risks of not addressing CVE-2017-16388?
Failing to address CVE-2017-16388 may leave your system vulnerable to exploitation by attackers, leading to unauthorized access and data breaches.