CVE-2017-16416 is a critical out-of-bounds write vulnerability affecting Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, and 11.0.22 and earlier. This flaw, stemming from an out-of-range pointer offset in the EMF+ image conversion module, allows an attacker to corrupt sensitive data or execute arbitrary code. With a CVSS score of 8.8 (High) and a FAUCET Risk Score of 86/100, it presents a significant threat requiring user interaction for exploitation. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it's not listed in the KEV catalog, the vulnerability has received limited community discussion and media coverage, indicating some awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.0.22CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 17.0, <= 17.011.30066CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= -, <= 17.012.20098CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 15.0, <= 15.006.30355CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
<= 11.0.22CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.