CVE-2018-16011 is a critical use-after-free vulnerability affecting Adobe Acrobat and Reader versions 2019.010.20064 and earlier, 2017.011.30110 and earlier, and 2015.006.30461 and earlier. This flaw, rated with a CVSS score of 8.8 (High), allows for arbitrary code execution through user interaction, typically via a malicious PDF document. While no public exploits are currently available in Metasploit or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, indicating awareness. It is not listed in CISA's KEV catalog, suggesting no widespread active exploitation at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.006.30060, <= 15.006.30461CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 15.008.20082, <= 19.010.20064CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 17.011.30056, <= 17.011.30110CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 15.006.30060, <= 15.006.30461CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* | ||
>= 15.008.20082, <= 19.010.20064CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.