CVE-2017-16391: Out-of-bounds Read
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is a result of untrusted input that is used to calculate an array index; the calculation occurs in the printing functionality. The vulnerability leads to an operation that can write to a memory location that is outside of the memory addresses allocated for the data structure. The specific scenario leads to a write access to a memory location that does not belong to the relevant process address space.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16391?
CVE-2017-16391 has a severity rating of critical, as it can allow an attacker to execute arbitrary code on the affected system.
How do I fix CVE-2017-16391?
To fix CVE-2017-16391, you should update Adobe Acrobat and Reader to the latest version available.
What versions of Adobe Acrobat and Reader are affected by CVE-2017-16391?
CVE-2017-16391 affects Adobe Acrobat versions 11.0.22 and earlier, as well as multiple versions of Adobe Acrobat DC and Reader.
Can I still use Adobe Acrobat if I have CVE-2017-16391?
Using an affected version of Adobe Acrobat with CVE-2017-16391 presents a security risk, and it is advisable to update immediately.
What types of attacks are possible due to CVE-2017-16391?
CVE-2017-16391 could potentially allow remote attackers to execute arbitrary code through specially crafted PDF files.