cbcvebase.
CVE-2016-1077
published 2016-05-11

CVE-2016-1077: Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before…

PriorityP264critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
17.41%
96.8th percentile
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1037, CVE-2016-1063, CVE-2016-1064, CVE-2016-1071, CVE-2016-1072, CVE-2016-1073, CVE-2016-1074, CVE-2016-1076, CVE-2016-1078, CVE-2016-1080, CVE-2016-1081, CVE-2016-1082, CVE-2016-1083, CVE-2016-1084, CVE-2016-1085, CVE-2016-1086, CVE-2016-1088, CVE-2016-1093, CVE-2016-1095, CVE-2016-1116, CVE-2016-1118, CVE-2016-1119, CVE-2016-1120, CVE-2016-1123, CVE-2016-1124, CVE-2016-1125, CVE-2016-1126, CVE-2016-1127, CVE-2016-1128, CVE-2016-1129, CVE-2016-1130, CVE-2016-4088, CVE-2016-4089, CVE-2016-4090, CVE-2016-4093, CVE-2016-4094, CVE-2016-4096, CVE-2016-4097, CVE-2016-4098, CVE-2016-4099, CVE-2016-4100, CVE-2016-4101, CVE-2016-4103, CVE-2016-4104, and CVE-2016-4105.

Affected

12 ranges
VendorProductVersion rangeFixed in
adobeacrobat<= 11.0.15
adobeacrobat<= 11.0.16
adobeacrobat_dc<= 15.006.30121
adobeacrobat_dc<= 15.010.20060
adobeacrobat_dc<= 15.006.30174
adobeacrobat_dc<= 15.016.20045
adobeacrobat_reader_dc<= 15.006.30121
adobeacrobat_reader_dc<= 15.010.20060
adobeacrobat_reader_dc<= 15.006.30174
adobeacrobat_reader_dc<= 15.016.20045
adobereader<= 11.0.15
adobereader<= 11.0.16

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://plmsecurity.net/sites/plmsecurity.net/files/APSB16-14_PoC.pdf
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/39799.zip
  • Trigger is a specially crafted image XObject inside a PDF file; inspect PDF streams for malformed/anomalous image XObject definitions
  • Vulnerable versions: Adobe Reader DC 15.010.20060 and earlier; flag process execution of AcroRd32.exe / Acrobat.exe versions prior to 15.016.20039 (Continuous) or 15.006.30172 (Classic) or 11.0.16
  • ·The CVE affects both Windows and OS X platforms; detection rules should be scoped to both operating systems
  • ·CVE-2016-1077 is one of many memory-corruption CVEs sharing the same advisory (APSB16-14); the NVD source document is for CVE-2016-4097 which lists CVE-2016-1077 as a related-but-distinct vulnerability — ensure CVE attribution is not conflated when building detection logic

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.