CVE-2016-7886 is a critical memory corruption vulnerability affecting Adobe InDesign versions 11.4.1 and earlier, and InDesign Server 11.0.0 and earlier, potentially leading to arbitrary code execution. With a CVSS score of 9.8, it is easily exploitable over a network with no user interaction, granting full confidentiality, integrity, and availability impact. While no public exploit code or active exploitation has been observed, its high EPSS and FAUCET scores indicate a significant potential risk. Community discussion and media coverage are minimal, suggesting limited public awareness despite its severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.4.1CPE matchmatch criteria | cpe:2.3:a:adobe:indesign:*:*:*:*:*:*:*:* | ||
<= 11.0.0CPE matchmatch criteria | cpe:2.3:a:adobe:indesign_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.