CVE-2016-4202 is a memory corruption vulnerability affecting Adobe Reader and Acrobat on Windows and OS X, specifically versions before 11.0.17, DC Classic before 15.006.30198, and DC Continuous before 15.017.20050. This high-severity vulnerability (CVSS 8.8) allows unauthenticated attackers to execute arbitrary code or cause a denial of service through user interaction, indicating a significant impact on confidentiality, integrity, and availability. While the vulnerability has a high FAUCET Risk Score of 74/100, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing. Despite limited community discussion and media coverage, Adobe released updates to address this and numerous other security flaws.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.0.16CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
<= 15.006.30174CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
<= 15.016.20045CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
<= 15.006.30174CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* | ||
<= 15.016.20045CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.