← All CVEs

CVE-2017-16381

high · 8.8

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value when processing TIFF files embedded within an XPS document. Crafted TIFF image input causes a mismatch between allocated buffer size and the access allowed by the computation. If an attacker can adequately control the accessible memory then this vulnerability can be leveraged to achieve arbitrary code execution.

8.8
CVSS
12.8%
EPSS (exploit prob.)
96th
EPSS percentile
2017-12-09
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
adobeacrobat<= 11.0.22
adobeacrobat>= 17.0, <= 17.011.30066
adobeacrobat_dc>= -, <= 17.012.20098
adobeacrobat_dc>= 15.0, <= 15.006.30355
adobeacrobat_reader<= 11.0.22
adobeacrobat_reader>= 17.0, <= 17.011.30066
adobeacrobat_reader_dc>= -, <= 17.012.20098
adobeacrobat_reader_dc>= 15.0, <= 15.006.30355

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-16381