« Back to list

CVE-2017-16416

Status: ModifiedHigh (8.8)—

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a computation that writes data past the end of the intended buffer; the computation is part of the image conversion module that handles Enhanced Metafile Format Plus (EMF+) data. The vulnerability is a result of an out of range pointer offset that is used to access sub-elements of an internal data structure. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (4)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2017-16416",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@adobe.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Adobe Acrobat Reader 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, 11.0.22 and earlier versions",
          "versions": [
            {
              "status": "affected",
              "version": "Adobe Acrobat Reader 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, 11.0.22 and earlier versions"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-12-09T06:29:02.897",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/101812",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1039791",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://helpx.adobe.com/security/products/acrobat/apsb17-36.html",
      "tags": [
        "Broken Link"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/101812",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1039791",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://helpx.adobe.com/security/products/acrobat/apsb17-36.html",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a computation that writes data past the end of the intended buffer; the computation is part of the image conversion module that handles Enhanced Metafile Format Plus (EMF+) data. The vulnerability is a result of an out of range pointer offset that is used to access sub-elements of an internal data structure. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code."
    },
    {
      "lang": "es",
      "value": "Se ha descubierto un problema en Adobe Acrobat y Reader: 2017.012.20098 y versiones anteriores, 2017.011.30066 y versiones anteriores, 2015.006.30355 y versiones anteriores y 11.0.22 y versiones anteriores. La vulnerabilidad se debe a un cálculo que escribe datos más allá del final del búfer planeado; el cálculo forma parte del módulo de conversión de imágenes que manipula datos en formato Enhanced Metafile Format Plus (EMF+). La vulnerabilidad es el resultado de un offset de puntero fuera de rango que se emplea para acceder a subelementos de una estructura de datos interna. Un atacante podría aprovechar esta vulnerabilidad para corromper datos sensibles o ejecutar código arbitrario."
    }
  ],
  "lastModified": "2026-06-17T01:09:20.943",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43C26AAA-3620-4229-AEFC-78AB3B2AAACF",
              "versionEndIncluding": "11.0.22"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2AD1E919-28D9-4C88-B8F9-95E062E9F9D0",
              "versionEndIncluding": "17.011.30066",
              "versionStartIncluding": "17.0"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43E90FF1-8078-4B18-A492-507E6129D10D",
              "versionEndIncluding": "17.012.20098",
              "versionStartIncluding": "-"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E45BE50E-04BE-49BE-8AFD-DFFAE6D11538",
              "versionEndIncluding": "15.006.30355",
              "versionStartIncluding": "15.0"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA8E1E9D-FE27-4916-9BB3-D3E92BBB5641",
              "versionEndIncluding": "11.0.22"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9346604B-ADB0-471B-9F81-8560E3F516AA",
              "versionEndIncluding": "17.011.30066",
              "versionStartIncluding": "17.0"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2A50612A-DC1B-4F64-BF9F-748A15EC6610",
              "versionEndIncluding": "17.012.20098",
              "versionStartIncluding": "-"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "394E8F26-2B1C-47ED-85F9-32BC5E04EC3A",
              "versionEndIncluding": "15.006.30355",
              "versionStartIncluding": "15.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@adobe.com"
}