CVE-2017-16388 is a use-after-free vulnerability in the JavaScript API engine of Adobe Acrobat and Reader, affecting multiple versions including 2017.012.20098 and earlier. This high-severity flaw (CVSS 8.8) can be exploited remotely with low complexity, requiring user interaction, and could lead to arbitrary code execution, control-flow hijack, or information leaks. While not listed in CISA's KEV catalog, its EPSS score indicates a higher-than-average probability of exploitation. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), but it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.0.22CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 17.0, <= 17.011.30066CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= -, <= 17.012.20098CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 15.0, <= 15.006.30355CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
<= 11.0.22CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.