CVE-2017-16381
The vulnerability is caused by a buffer access with an incorrect length value when processing TIFF files embedded within an XPS document.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.8%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value when processing TIFF files embedded within an XPS document. Crafted TIFF image input causes a mismatch between allocated buffer size and the access allowed by the computation. If an attacker can adequately control the accessible memory then this vulnerability can be leveraged to achieve arbitrary code execution.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 12.85% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- adobe/acrobat · adobe/acrobat dc · adobe/acrobat reader · adobe/acrobat reader dc
- Source
- psirt@adobe.com
References
- http://www.securityfocus.com/bid/101831Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039791Third Party Advisory, VDB Entry
- https://helpx.adobe.com/security/products/acrobat/apsb17-36.htmlVendor Advisory
- http://www.securityfocus.com/bid/101831Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039791Third Party Advisory, VDB Entry
- https://helpx.adobe.com/security/products/acrobat/apsb17-36.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.