CVE-2017-16395 is a critical buffer access vulnerability in Adobe Acrobat and Reader (multiple versions) that arises from incorrect length values during Enhanced Metafile Format (EMF) image conversion. This flaw, rated 8.8 HIGH on CVSS, allows an unauthenticated attacker to achieve arbitrary code execution by tricking a user into opening a specially crafted EMF file. While no public exploit code or active exploitation has been confirmed, its high severity and potential for complete compromise of confidentiality, integrity, and availability warrant immediate patching. The vulnerability has garnered some media attention and community discussion, indicating awareness within the security landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.0.22CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 17.0, <= 17.011.30066CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= -, <= 17.012.20098CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 15.0, <= 15.006.30355CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
<= 11.0.22CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.