CVE-2016-1052 is a critical use-after-free vulnerability affecting Adobe Reader and Acrobat on both Windows and OS X, specifically versions prior to 11.0.16, 15.006.30172 (Classic), and 15.016.20039 (Continuous). This flaw allows unauthenticated attackers to execute arbitrary code remotely without user interaction. With a CVSSv3 score of 9.8 (CRITICAL), the vulnerability presents a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Successful exploitation could lead to complete system compromise. Despite its critical severity, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on CISA's KEV catalog. Community discussion and media coverage are minimal, suggesting a lack of widespread attention or active exploitation at present.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.0.15CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
<= 15.006.30121CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
<= 15.010.20060CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
<= 15.006.30121CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* | ||
<= 15.010.20060CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.