VYPR
High severity8.8NVD Advisory· Published Dec 9, 2017· Updated May 13, 2026

CVE-2017-16403

CVE-2017-16403

Description

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of the image conversion module that processes Enhanced Metafile Format Plus (EMF+) data. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.

Affected products

6
  • cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
    Range: <=11.0.22
  • cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:*+ 1 more
    • cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:*range: >=15.0,<=15.006.30355
    • cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*range: >=-,<=17.012.20098
  • cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
    Range: <=11.0.22
  • cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:*+ 1 more
    • cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:*range: >=15.0,<=15.006.30355
    • cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*range: >=-,<=17.012.20098

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.