CVE-2017-16367Incorrect Type Conversion or Cast in Adobe Acrobat

Severity
8.8HIGHNVD
EPSS
8.7%
top 7.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9
Latest updateMay 17

Description

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a type confusion overflow vulnerability. The vulnerability leads to an out of bounds memory access. Attackers can exploit the vulnerability by using the out of bounds access for unintended reads or writes -- potentially leading to code corruption, control-flow hija

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

NVDadobe/acrobat_reader17.017.011.30066+1
NVDadobe/acrobat_reader_dc-17.012.20098+1
NVDadobe/acrobat17.017.011.30066+1
NVDadobe/acrobat_dc-17.012.20098+1

🔴Vulnerability Details

2
GHSA
GHSA-xvmr-xj68-h5hr: An issue was discovered in Adobe Acrobat and Reader: 20172022-05-17
CVEList
CVE-2017-16367: An issue was discovered in Adobe Acrobat and Reader: 20172017-12-09

🕵️Threat Intelligence

3
Talos
Microsoft Patch Tuesday - November 20172017-11-14
Talos
Microsoft Patch Tuesday - November 20172017-11-14
Zscaler
Zscaler protects against 40 new vulnerabilities for Adobe Fl
CVE-2017-16367 — Incorrect Type Conversion or Cast | cvebase