CVE-2016-4195 is a critical memory corruption vulnerability affecting Adobe Reader and Acrobat on both Windows and OS X platforms. Specifically, it impacts Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050. This vulnerability allows unauthenticated attackers to execute arbitrary code or cause a denial of service through unspecified vectors, requiring user interaction. With a CVSSv3 score of 8.8 (High), this vulnerability presents a significant risk. Its attack vector is network-based with low attack complexity, and successful exploitation can lead to high impacts on confidentiality, integrity, and availability. The Common Weakness Enumeration (CWE) associated with this vulnerability is CWE-119, indicating a buffer overflow or similar memory corruption issue. Currently, there is no evidence of active exploitation in the wild, and no public exploit code is available via Metasploit, Nuclei, or ExploitDB. Despite its age, community discussion and media coverage indicate some awareness, with one article from BleepingComputer highlighting Adobe's updates addressing numerous security vulnerabilities, including this one.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.0.16CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
<= 15.006.30174CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
<= 15.016.20045CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
<= 15.006.30174CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* | ||
<= 15.016.20045CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.