cbcvebase.
CVE-2016-4203
published 2016-07-13

CVE-2016-4203: Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before…

PriorityP266critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
27.12%
97.8th percentile
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4191, CVE-2016-4192, CVE-2016-4193, CVE-2016-4194, CVE-2016-4195, CVE-2016-4196, CVE-2016-4197, CVE-2016-4198, CVE-2016-4199, CVE-2016-4200, CVE-2016-4201, CVE-2016-4202, CVE-2016-4204, CVE-2016-4205, CVE-2016-4206, CVE-2016-4207, CVE-2016-4208, CVE-2016-4211, CVE-2016-4212, CVE-2016-4213, CVE-2016-4214, CVE-2016-4250, CVE-2016-4251, CVE-2016-4252, and CVE-2016-4254.

Affected

6 ranges
VendorProductVersion rangeFixed in
adobeacrobat<= 11.0.16
adobeacrobat_dc<= 15.006.30174
adobeacrobat_dc<= 15.016.20045
adobeacrobat_reader_dc<= 15.006.30174
adobeacrobat_reader_dc<= 15.016.20045
adobereader<= 11.0.16

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/40097.zip
processAcroRd32.exe
otherCoolType!CTInit+0x45ef1
  • The vulnerability is triggered by opening a specially crafted PDF file containing an invalid TrueType font (.ttf) with invalid data, causing memory corruption in the CoolType font engine (CoolType.dll) within Adobe Reader/Acrobat DC.
  • The malicious PDF embeds a crafted TrueType font in a stream object (obj 17) encoded with FlateDecode. The font file differs from a benign version by a single byte at offset 0x30e3, which corrupts the simple glyph structure (endPtsOfContours, instructionLength, flags fields). Inspect embedded font streams in PDFs for anomalous TrueType glyph data.
  • Fortinet IPS signature available for network-level detection of exploit attempts targeting this vulnerability.
  • ·CVE-2016-4203 affects Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X. The PoC was confirmed against version 15.016.20045.
  • ·The vulnerability requires user interaction — the victim must open a specially crafted PDF file. It is not exploitable without this interaction.
  • ·The fix was released by Adobe on July 12, 2016 as part of security bulletin APSB16-26.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.