CVE-2017-16398: Use After Free
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the JavaScript engine. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption, control-flow hijack, or an information leak attack. Successful exploitation could lead to arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16398?
CVE-2017-16398 has a high severity rating due to its potential to be exploited for arbitrary code execution.
How do I fix CVE-2017-16398?
To fix CVE-2017-16398, users should update Adobe Acrobat and Reader to the latest version available.
Which Adobe products are affected by CVE-2017-16398?
CVE-2017-16398 affects Adobe Acrobat and Reader versions up to 11.0.22, 2015.006.30355, 2017.011.30066, and 2017.012.20098.
Can CVE-2017-16398 be exploited remotely?
Yes, CVE-2017-16398 can be exploited remotely if a user opens a malicious PDF file.
What type of vulnerability is CVE-2017-16398?
CVE-2017-16398 is classified as a use after free vulnerability in the JavaScript engine of Adobe Acrobat and Reader.