CVE-2017-16378 is a high-severity vulnerability affecting multiple versions of Adobe Acrobat and Reader products. It stems from an uninitialized pointer access during internal AST thread manipulation, leading to a read from an unexpected memory location. This allows an unauthenticated attacker to potentially read sensitive memory, with a CVSS score of 8.8. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has received some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.0.22CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 17.0, <= 17.011.30066CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= -, <= 17.012.20098CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 15.0, <= 15.006.30355CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
<= 11.0.22CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.