Learn about CVE-2017-16390 affecting Adobe Acrobat and Reader versions, allowing attackers to execute arbitrary code. Find mitigation steps and security practices to prevent exploitation.
Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, as well as 11.0.22 and earlier, contain a use after free vulnerability in the JavaScript engine API. This vulnerability could allow an attacker to execute arbitrary code.
Understanding CVE-2017-16390
Adobe Acrobat and Reader versions are affected by a use after free vulnerability in the JavaScript engine API, potentially leading to code execution.
What is CVE-2017-16390?
A use after free vulnerability in Adobe Acrobat and Reader versions allows attackers to gain unintended memory access, leading to potential code corruption, control-flow hijacking, or information leak attacks.
The Impact of CVE-2017-16390
If successfully exploited, this vulnerability could result in the execution of arbitrary code, posing a significant security risk to affected systems.
Technical Details of CVE-2017-16390
Adobe Acrobat and Reader versions are susceptible to a use after free vulnerability in the JavaScript engine API.
Vulnerability Description
The use after free vulnerability occurs due to a mismatch between old and new objects, enabling attackers to gain unintended memory access.
Affected Systems and Versions
Exploitation Mechanism
Attackers can exploit this vulnerability by manipulating the JavaScript engine API, potentially leading to code corruption, control-flow hijacking, or information leak attacks.
Mitigation and Prevention
To address CVE-2017-16390, users and organizations should take immediate steps and implement long-term security practices.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates