CVE-2016-4204 is a critical memory corruption vulnerability affecting Adobe Reader and Acrobat products across Windows and OS X, including specific versions of Adobe Reader and Acrobat DC Classic and Continuous. This vulnerability allows unauthenticated attackers to execute arbitrary code or cause a denial of service via unspecified vectors. With a CVSS score of 9.8 (CRITICAL) and a FAUCET Risk Score of 97/100, it presents a significant risk due to its network-based attack vector, low attack complexity, and high potential for impact on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, an ExploitDB entry (EDB-40096) exists, indicating public exploit code availability. The vulnerability has garnered community discussion and media coverage, suggesting awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.0.16CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
<= 15.006.30174CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
<= 15.016.20045CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
<= 15.006.30174CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* | ||
<= 15.016.20045CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.