KLA10838
Multiple vulnerabilities in Adobe Acrobat & Reader
Updated: 01/04/2019
CVSS
?
10.0
Detect date
?
07/12/2016
Severity
?
Critical
Description

Multiple serious vulnerabilities have been found in Adobe products. Malicious users can exploit these vulnerabilities to execute arbitrary code, bypass security restrictions or cause a denial of service.

Below is a complete list of vulnerabilities

  1. Integer overflow, use-after-free, buffer overflow and multiple memory corruption vulnerabilities can be exploited remotely to execute arbitrary code;
  2. An unknown vulnerability at Javascript API can be exploited remotely to bypass security restrictions.
  3. Memory corruption vulnerability can be exploited remotely to cause denial of service.
Affected products

Adobe Acrobat DC Continuous versions earlier than 15.017.20050
Adobe Acrobat Reader DC Continuous versions earlier than 15.017.20050
Adobe Acrobat DC Classic versions earlier than 15.006.30198
Adobe Acrobat Reader DC Classic versions earlier than 15.006.30198
Adobe Acrobat XI versions earlier than 11.0.17
Adobe Reader XI versions earlier than 11.0.17

Solution

Update to the latest version
Get Adobe Reader

Original advisories

Adobe security advisory

Impacts
?
ACE 
[?]

DoS 
[?]

SB 
[?]
Related products
Adobe Reader XI
Adobe Acrobat XI
Adobe Acrobat Reader DC Continuous
Adobe Acrobat Reader DC Classic
Adobe Acrobat DC Continuous
Adobe Acrobat DC Classic
CVE-IDS
?

CVE-2016-4255
CVE-2016-4254
CVE-2016-4252
CVE-2016-4251
CVE-2016-4250
CVE-2016-4202
CVE-2016-4203
CVE-2016-4204
CVE-2016-4205
CVE-2016-4206
CVE-2016-4207
CVE-2016-4209
CVE-2016-4210
CVE-2016-4191
CVE-2016-4192
CVE-2016-4193
CVE-2016-4194
CVE-2016-4195
CVE-2016-4196
CVE-2016-4197
CVE-2016-4198
CVE-2016-4199
CVE-2016-4200
CVE-2016-4201
CVE-2016-4265
CVE-2016-4266
CVE-2016-4267
CVE-2016-4268
CVE-2016-4269
CVE-2016-4270
CVE-2016-4208
CVE-2016-6938
CVE-2016-6937
CVE-2016-4211
CVE-2016-4212
CVE-2016-4213
CVE-2016-4214
CVE-2016-4215