CVE-2017-16395
Description
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value in the image conversion module when processing Enhanced Metafile Format (EMF). Crafted EMF input (EMR_STRETCHDIBITS) causes a mismatch between allocated buffer size and the access allowed by the computation. If an attacker can adequately control the accessible memory then this vulnerability can be leveraged to achieve arbitrary code execution.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 90 Days)
Improper Restriction of Operations within the Bounds of a Memory Buffer
StableCommon Consequences
Applicable Platforms
Acrobat Reader Dc by Adobe
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
Acrobat by Adobe
cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
Acrobat Reader Dc by Adobe
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:*
Acrobat by Adobe
cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
Acrobat Dc by Adobe
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
Acrobat Reader by Adobe
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
Acrobat Dc by Adobe
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:*
Acrobat Reader by Adobe
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*