BlackTreeCVE Intelligence
← Back to the CVE catalogue
Full vulnerability report · 2017
CVE-2017-16377High confidence

This vulnerability is due to a computation that accesses a pointer that has not been initialized in the main DLL

Unknown · Adobe Acrobat Reader 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, 11.0.22 and earlier versions

Official source article: Adobe APSB17-36 ↗. Check the applicable product and release in the original source.

8.8HighCVSS 3.0
Recommended action
Within 7 days

High technical severity; prioritise exposed affected systems while verifying vendor guidance.

Fix not verified
R
Operational reassessment

Published severity in operational context

Open reassessment dashboard →
Published severityHighOperational priority:High, unchanged from published severity.unchanged

Evidence used

  • No CISA KEV confirmation is currently recorded.
  • EPSS is 6.77% for the current model date.

Compensating controls

  • Restrict the affected network interface to trusted sources where business-safe.
  • Monitor vendor guidance and exploitation sources for a material change.

Verification

  1. Confirm that the asset runs Unknown Adobe Acrobat Reader 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, 11.0.22 and earlier versions and falls inside the recorded affected range.
  2. Recheck the vendor advisory before scheduling a change because no verified fixed version is currently retained.
  3. Validate exposure, authentication requirements and compensating controls in the actual environment.
  4. Reopen this reassessment when CVSS, KEV, EPSS, exploit evidence or remediation changes.
Mitigation target: Within 30 daysRemediation target: Within 180 days

This automated reassessment organises public evidence. It does not know asset exposure, business impact or control effectiveness and does not replace CVSS or a human risk decision.

Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Choose official national sources for this report. Each advisory shows its original language. Your selection is remembered on this device and included in shared links.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2017-7571

No EUVD known-exploited evidence

ENISA has published the identifier mapping but no EUVD description has been stored yet.

EUVD state
Present in the current official mapping
Known exploitation
Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
ENISA score
Not supplied in the stored EUVD record
Advisory evidence
No linked advisory details stored yet
Recommended actionWithin 7 days

High technical severity; prioritise exposed affected systems while verifying vendor guidance.

Fix not verified
01

What, why and how

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is due to a computation that accesses a pointer that has not been initialized in the main DLL. In this case, a computation defines a read from an unexpected memory location. Therefore, an attacker might be able to read sensitive portions of memory.

What

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is due to a computation that accesses a pointer that has not been initialized in the main DLL. In this case, a computation defines a read from an unexpected memory location. Therefore, an attacker might be able to read sensitive portions of memory.

Why

The product accesses or uses a pointer that has not been initialized.

How

An attacker operating through a network path may attempt exploitation without authentication after a user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

What

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is due to a computation that accesses a pointer that has not been initialized in the main DLL. In this case, a computation defines a read from an unexpected memory location. Therefore, an attacker might be able to read sensitive portions of memory.

Why

The product accesses or uses a pointer that has not been initialized.

How

An attacker operating through a network path may attempt exploitation without authentication after a user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
No confirmed evidence

No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
None recorded

No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.

Likely attack path
a network path → Access of Uninitialized Pointer → cause the confidentiality, integrity or availability impact described by the vendor
Attack surface
Network
Privileges required
None: unauthenticated exploitation is possible
User interaction
Required interaction required
Attack complexity
Low: no specialised conditions are recorded
Security boundary
Unchanged: impact remains within the vulnerable component's security authority
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-824 ↗

CWE-824: Access of Uninitialized Pointer. The product accesses or uses a pointer that has not been initialized.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Common Vulnerability Scoring System 3.0: the compact vector below is decoded into plain language.

AVNetworkAttack vector: The vulnerable component can be reached over a network.ACLowAttack complexity: No specialised conditions are required beyond attacker-controlled input.PRNonePrivileges required: The attacker does not need an account or existing privileges.UIRequiredUser interaction: Another user must perform an action for exploitation to succeed.SUnchangedScope: The security impact remains within the vulnerable component's authority.CHighConfidentiality impact: A successful attack can cause a major loss.IHighIntegrity impact: A successful attack can cause a major loss.AHighAvailability impact: A successful attack can cause a major loss.
Post-exploitation / living off the land
No specific living-off-the-land technique is confirmed in the structured sources. Monitor normal administration tools for activity inconsistent with the affected service's baseline.
NetworkUnauthenticatedCWE-824
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

Canadian Centre for Cyber Security · English · AV17-168Adobe security updates

pose of this advisory is to bring attention to multiple Adobe Security updates for various products. Assessment Adobe has released the following security bulletins: APSB17-33 - Adobe Flash Player APSB17-34 - Photoshop CC APSB17-35 - Adobe Connect APSB17-36 - Adobe Acrobat and Reader APSB17-37 - Adobe DNG Converter APSB17-38 - InDesign APSB17-39 - Adobe Digital Editions APSB17-40 - Adobe Shockwave Player APSB17-41 - Adobe Experience Manager CVE References: CVE-2017-3112, CVE-2017-3114, CVE-2017-11213, CVE-2017-11215, CVE-2017-11225, CVE-2017-11303, CVE-2017-11304, CVE-2017-11291, CVE-2017-11287, CVE-2017-11288, CVE-2017-11289, CVE-2017-11290, CVE-2017-16377, CVE-2017-16378, CVE-2017-16360, CVE-2017-16388, CVE-2017-16389, CVE-2017-16390, CVE-2017-16393, CVE-2017-16398, CVE-2017-16381, CVE-2017-16385, CVE-2017-16392, CVE-2017-16395, CVE-2017-16396, CVE-2017-16363, CVE-2017-16365, CVE-2017-16374, CVE-2017-16384, CVE-2017-16386, CVE-2017-16387, CVE-2017-16368, CVE-2017-16383, CVE-2017-16391, CVE-2017-16410, CVE-2017-16362, CVE-2017-16370, CVE-2017-16376, CVE-2017-16382, CVE-2017-16394, CVE-2017-16397, CVE-2017-16399, CVE-2017-16400, CVE-2017-16401, CVE-2017-16402, CVE-2017-16403, CVE-2017-16404, CVE-2017-16405, CVE-2017-16408, CVE-2017-16409, CVE-2017-16412, CVE-2017-16414, CVE-2017-16417, CVE-2017

Official advisory ↗
CERT-FR · French · CERTFR-2017-AVI-414Multiples vulnérabilités dans Adobe Acrobat et Reader

d?id=CVE-2017-16368 Référence CVE CVE-2017-16369 https://www.cve.org/CVERecord?id=CVE-2017-16369 Référence CVE CVE-2017-16370 https://www.cve.org/CVERecord?id=CVE-2017-16370 Référence CVE CVE-2017-16371 https://www.cve.org/CVERecord?id=CVE-2017-16371 Référence CVE CVE-2017-16372 https://www.cve.org/CVERecord?id=CVE-2017-16372 Référence CVE CVE-2017-16373 https://www.cve.org/CVERecord?id=CVE-2017-16373 Référence CVE CVE-2017-16374 https://www.cve.org/CVERecord?id=CVE-2017-16374 Référence CVE CVE-2017-16375 https://www.cve.org/CVERecord?id=CVE-2017-16375 Référence CVE CVE-2017-16376 https://www.cve.org/CVERecord?id=CVE-2017-16376 Référence CVE CVE-2017-16377 https://www.cve.org/CVERecord?id=CVE-2017-16377 Référence CVE CVE-2017-16378 https://www.cve.org/CVERecord?id=CVE-2017-16378 Référence CVE CVE-2017-16379 https://www.cve.org/CVERecord?id=CVE-2017-16379 Référence CVE CVE-2017-16380 https://www.cve.org/CVERecord?id=CVE-2017-16380 Référence CVE CVE-2017-16381 https://www.cve.org/CVERecord?id=CVE-2017-16381 Référence CVE CVE-2017-16382 https://www.cve.org/CVERecord?id=CVE-2017-16382 Référence CVE CVE-2017-16383 https://www.cve.org/CVERecord?id=CVE-2017-16383 Référence CVE CVE-2017-16384 https://www.cve.org/CVERecord?id=CVE-2017-16384 Référence CVE CVE-2017-16385 https://www.cve.org/CVERecord?id=

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-013324Adobe Reader および Acrobat におけるヒープオーバーフローの脆弱性

Adobe Reader および Acrobat には、ヒープオーバーフローの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-013323Adobe Reader および Acrobat における境界外読み取りに関する脆弱性

Adobe Reader および Acrobat には、境界外読み取りに関する脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-013322Adobe Reader および Acrobat における境界外読み取りに関する脆弱性

Adobe Reader および Acrobat には、境界外読み取りに関する脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-013321Adobe Reader および Acrobat における境界外読み取りに関する脆弱性

Adobe Reader および Acrobat には、境界外読み取りに関する脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-013320Adobe Reader および Acrobat における境界外読み取りに関する脆弱性

Adobe Reader および Acrobat には、境界外読み取りに関する脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-013319Adobe Reader および Acrobat における境界外読み取りに関する脆弱性

Adobe Reader および Acrobat には、境界外読み取りに関する脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010766Adobe Reader および Acrobat におけるメモリを破損される脆弱性

Adobe Reader および Acrobat には、メモリを破損される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010719Adobe Reader および Acrobat の WebCapture モジュールにおける重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat の WebCapture モジュールは、対象のバッファの終端を越えてデータを読み取るため、重要な情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010718Adobe Reader および Acrobat における重要な情報を破損される脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを書き込まれるため、重要な情報を破損される、または任意のコードを実行される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010717Adobe Reader および Acrobat の EMF processing モジュールにおけるメモリの境界外アクセスを引き起こされる脆弱性

Adobe Reader および Acrobat の EMF processing モジュールは、型の取り違え (type confusion) により、互換性のない型を使用するオブジェクトにアクセスするため、メモリの境界外アクセスを引き起こされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010716Adobe Reader および Acrobat のページ表示機能における重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat のページ表示機能は、対象のバッファの終端を越えてデータを読み取るため、重要な情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010715Adobe Reader および Acrobat における重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを読み取るため、重要な情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010714Adobe Reader および Acrobat における重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを読み取るため、重要な情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010713Adobe Reader および Acrobat における重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを読み取るため、重要な情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010712Adobe Reader および Acrobat における重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを読み取るため、重要な情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010711Adobe Reader および Acrobat の JPEG 2000 パーサにおける重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat の JPEG 2000 パーサは、対象のバッファの終端を越えてデータを読み取るため、重要な情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010710Adobe Reader および Acrobat の XPS 構文解析モジュールにおける重要なデータを漏えいされる脆弱性

Adobe Reader および Acrobat の XPS 構文解析モジュールには、信頼されないポインタデリファレンスにより、重要なデータを漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010709Adobe Reader および Acrobat の MakeAccesible プラグインにおける境界外読み取りの脆弱性

Adobe Reader および Acrobat の MakeAccesible プラグインには、フォントデータを処理する際、境界外読み取りの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010692Adobe Reader および Acrobat における重要なデータを破壊される脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを書き込まれるため、重要なデータを破壊される、または任意のコードを実行される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010691Adobe Reader および Acrobat における重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを読み取るため、重要な情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010690Adobe Reader および Acrobat における重要なデータを破壊される脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを書き込まれるため、重要なデータを破壊される、または任意のコードを実行される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010689Adobe Reader および Acrobat における重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを読み取るため、重要な情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010688Adobe Reader および Acrobat における重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを読み取るため、重要な情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010687Adobe Reader および Acrobat におけるデータ構造体に割り当てられたメモリアドレスの外部にあるメモリロケーションに書き込まれる脆弱性

Adobe Reader および Acrobat には、データ構造体に割り当てられたメモリアドレスの外部にあるメモリロケーションに書き込まれる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010685Adobe Reader および Acrobat における重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを読み取るため、重要な情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010686Adobe Reader および Acrobat における重要なデータを破壊される脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを書き込まれるため、重要なデータを破壊される、または任意のコードを実行される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010684Adobe Reader および Acrobat の JPEG 2000 モジュールにおける重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat の JPEG 2000 モジュールは、対象のバッファの終端を越えてデータを読み取るため、重要な情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010683Adobe Reader および Acrobat における任意のコードを実行される脆弱性

Adobe Reader および Acrobat には、解放済みメモリの使用 (use-after-free) により、任意のコードを実行される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010682Adobe Reader および Acrobat における任意のコードを実行される脆弱性

Adobe Reader および Acrobat には、JPEG 処理モジュールの不正な長さのバッファアクセスによって、任意のコードを実行される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010681Adobe Reader および Acrobat におけるデータ構造体に割り当てられたメモリアドレスの外部にあるメモリロケーションに書き込まれる脆弱性

Adobe Reader および Acrobat には、データ構造体に割り当てられたメモリアドレスの外部にあるメモリロケーションに書き込まれる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010680Adobe Reader および Acrobat の JavaScript エンジン の API におけるコードを破損される脆弱性

Adobe Reader および Acrobat の JavaScript エンジン の API には、内部データ構造を作成する際、解放済みメモリの使用 (use-after-free) により、任意のコードを実行される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010679Adobe Reader および Acrobat の JavaScript エンジンにおける任意のコードを実行される脆弱性

Adobe Reader および Acrobat の JavaScript エンジンには、内部データ構造を作成する際、解放済みメモリの使用 (use-after-free) により、任意のコードを実行される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010678Adobe Reader および Acrobat の JavaScript の API エンジンにおける任意のコードを実行される脆弱性

Adobe Reader および Acrobat の JavaScript の API エンジンには、内部データ構造を作成する際、解放済みメモリの使用 (use-after-free) により、任意のコードを実行される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010677Adobe Reader および Acrobat における重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを読み取るため、重要な情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010676Adobe Reader および Acrobat における重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを読み取るため、重要な情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010675Adobe Reader および Acrobat における脆弱性

Adobe Reader および Acrobat には、XPS 変換処理中の TIFF 解析の際に不正な length 値を持つバッファにアクセスするため、任意のコードを実行される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010674Adobe Reader および Acrobat におけるバッファオーバーリードの脆弱性

Adobe Reader および Acrobat は、ポインタ演算がバッファの有効なメモリ外で計算するため、バッファオーバーリードの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010673Adobe Reader および Acrobat におけるヒープオーバーフローの脆弱性

Adobe Reader および Acrobat には、XPS ドキュメント内に埋め込まれた JPEG ファイルを処理する際、ヒープオーバーフローの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010672Adobe Reader および Acrobat における重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを読み取るため、重要な情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010671Adobe Reader および Acrobat における任意のコードを実行される脆弱性

Adobe Reader および Acrobat は、XPS ドキュメントに埋め込まれた TIFF ファイルの処理の際に不正な length 値を持つバッファにアクセスするため、任意のコードを実行される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010670Adobe Reader および Acrobat における特定のファイルタイプの拡張子のセキュリティを回避される脆弱性

Adobe Reader および Acrobat は、Acrobat がブラックリストおよびホワイトリストの両方を保持するが、両リストに載っていないファイル拡張子を警告プロンプトの表示後も開くため、特定のファイルタイプの拡張子のセキュリティを回避される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010669Adobe Reader および Acrobat における重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを読み取るため、重要な情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010668Adobe Reader および Acrobat における型の取り違えオーバーフローの脆弱性

Adobe Reader および Acrobat には、型の取り違え (type confusion) オーバーフローの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010666Adobe Reader および Acrobat の True Type2 フォント構文解析モジュールにおける重要な情報を取得される脆弱性

Adobe Reader および Acrobat の True Type2 フォント構文解析モジュールには、バッファオーバーリードにより、オブジェクトのヒープアドレスなどの重要な情報を取得される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010665Adobe Reader および Acrobat における重要なデータを漏えいされる脆弱性

Adobe Reader および Acrobat には、数字フォーマット辞書のエントリの際の信頼されないポインタデリファレンスにより、重要なデータを漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010664Adobe Reader および Acrobat におけるバッファオーバーリードの脆弱性

Adobe Reader および Acrobat には、バッファオーバーリードの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010662Adobe Reader および Acrobat における重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを読み取るため、重要な情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010661Adobe Reader および Acrobat における重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを読み取るため、重要な情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010660Adobe Reader および Acrobat における重要なデータを破壊される脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを書き込まれるため、重要なデータを破壊される、または任意のコードを実行される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010659Adobe Reader および Acrobat における任意のコードを実行される脆弱性

Adobe Reader および Acrobat には、解放済みメモリの使用 (use-after-free) により、任意のコードを実行される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010658Adobe Reader および Acrobat における重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えてデータを読み取るため、重要な情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010657Adobe Reader および Acrobat における任意のコードを実行される脆弱性

Adobe Reader および Acrobat は、割り当てられたバッファサイズおよび計算により許可されたアクセス権が一致しないため、任意のコードを実行される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010656Adobe Reader および Acrobat における任意のコードを実行される脆弱性

Adobe Reader および Acrobat は、Enhanced Metafile Format (EMF) を処理する際、割り当てられたバッファサイズおよび計算により許可されたアクセス権が一致しないため、任意のコードを実行される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010655Adobe Reader および Acrobat における重要な情報を漏えいされる脆弱性

Adobe Reader および Acrobat は、対象のバッファの終端を越えたデータを読み取るため、重要な情報を情報を漏えいされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010654Adobe Reader および Acrobat のグラフィックレンダリングエンジンにおける型の取り違えオーバーフローの脆弱性

Adobe Reader および Acrobat のグラフィックレンダリングエンジンには、型の取り違え (type confusion) により、オーバーフロー状態にされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010653Adobe Reader および Acrobat における重要なメモリの一部を読まれる脆弱性

Adobe Reader および Acrobat は、メイン DLL で初期化されていないポインタにアクセスされた際、想定外のメモリ位置から読み出しを定義するため、重要なメモリの一部を読まれる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010652Adobe Reader および Acrobat における重要なメモリの一部を読まれる脆弱性

Adobe Reader および Acrobat は、メイン DLL で初期化されていないポインタにアクセスされた際、想定外のメモリ位置から読み出しを定義するため、重要なメモリの一部を読まれる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010651Adobe Reader および Acrobat の JavaSscript API エンジンにおける信頼できないポインタのデリファレンスに関する脆弱性

Adobe Reader および Acrobat の JavaSscript API エンジンは、関連するプロセスアドレス空間に属さないメモリロケーションへポインタするため、信頼できないポインタのデリファレンスに関する脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010650Adobe Reader および Acrobat の JPEG 2000 モジュールにおけるバッファオーバーリードの脆弱性

Adobe Reader および Acrobat の JPEG 2000 モジュールは、無効な JPEG2000 入力コードストリームの場合、ポインタ演算がバッファの有効なメモリ外で計算するため、バッファオーバーリードの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010649Adobe Reader および Acrobat における信頼できないポインタのデリファレンスに関する脆弱性

Adobe Reader および Acrobat の JavaSscript API エンジンは、関連するプロセスアドレス空間に属さないメモリロケーションへポインタするため、信頼できないポインタのデリファレンスに関する脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010648Adobe Reader および Acrobat の JavaScript API エンジンにおける信頼できないポインタのデリファレンスに関する脆弱性

Adobe Reader および Acrobat の JavaSscript API エンジンは、関連するプロセスアドレス空間に属さないメモリロケーションへポインタするため、信頼できないポインタのデリファレンスに関する脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010647Adobe Reader および Acrobat の JavaScript エンジンにおける信頼できないポインタのデリファレンスに関する脆弱性

Adobe Reader および Acrobat の JavaSscript API エンジンは、関連するプロセスアドレス空間に属さないメモリロケーションへポインタするため、信頼できないポインタのデリファレンスに関する脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010645Adobe Reader および Acrobat の Unicode 文字列操作モジュールにおけるスタックベースのバッファオーバーフローの脆弱性

Adobe Reader および Acrobat の Unicode 文字列操作モジュールは、バッファへのポインタのオフセットを操作する際、不適切に確認するため、スタックベースのバッファオーバーフローの脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010644Adobe Reader および Acrobat における任意のコードを実行される脆弱性

Adobe Reader および Acrobat には、内部データ構造を作成する際、解放済みメモリの使用 (use-after-free) により、任意のコードを実行される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010667Adobe Reader および Acrobat の AcroPDF プラグインにおけるセキュリティを回避される脆弱性

Adobe Reader および Acrobat の AcroPDF プラグインには、セキュリティを回避される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010708Adobe Reader および Acrobat におけるセキュリティを回避される脆弱性

Adobe Reader および Acrobat には、XFDF ファイルを処理する際、セキュリティを回避される脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010663Adobe Reader および Acrobat における JavaScript API 内のスタックを枯渇状態にされる脆弱性

Adobe Reader および Acrobat は、システムリソースに関する再帰の量を正しく制御しないため、JavaScript API 内のスタックを枯渇状態にされる脆弱性が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2017-010646Adobe Reader および Acrobat における同一生成元ポリシーを回避される脆弱性

Adobe Reader および Acrobat には、同一生成元ポリシーを回避される脆弱性が存在します。

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-4817Adobe 제품군 신규 취약점 보안 업데이트 권고

- 원격 코드 실행으로 이어질 수 있는 초기화되지 않은 포인터에 접근하여 발생하는 취약점(CVE-2017-16377,

Official advisory ↗
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Fix not verified
Affected
Adobe Acrobat Reader 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, 11.0.22 and earlier versions: Adobe Acrobat Reader 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, 11.0.22 and earlier versions
Fixed
No fixed version is explicitly recorded in the structured CVE data.
Action
No verified patch reference is present in the current structured sources. Check the vendor advisory before making a change.
Workaround
No verified workaround is recorded. If business-safe, reduce exposure to the affected interface and allow only trusted sources until authoritative guidance is available.
04

Evidence and provenance

Published 9 Dec 2017 · Last source change 5 Aug 2024, 20:27 UTC · CWE-824 · Access of Uninitialized Pointer

CVE recordCVE.org · 5.1
CVSS sourceNIST NVD
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-09-01
European sourceENISA EUVD · EUVD-2017-7571
Product sourceCNA
Remediation sourceCVE/CNA references
CWE sourceNIST NVD
NVD statusNVD modified after enrichment

Missing structured fields: affected product. Missing data is not evidence of low risk; review the primary advisory.

Material change intelligence

What changed after publication

View recent updates ↗
  1. ENISA EUVD mappingEUVD-2017-7571 was added to the official ENISA EUVD mapping for this CVE.
    Before
    not recorded
    After
    {"euvdId":"EUVD-2017-7571"}
    ENISA EUVD ↗
  2. Vendor guidanceAuthoritative vendor guidance changed: added vendor advisory: helpx.adobe.com/apsb17-36.html.
    Before
    no authoritative guidance recorded
    After
    vendor advisory: helpx.adobe.com/apsb17-36.html
    helpx.adobe.com ↗
  3. SeveritySeverity changed from Unknown to High.
    Before
    Unknown
    After
    High
    NIST NVD ↗
  4. CVSS scoreCVSS score changed from not recorded to 8.8 (CVSS 3.0 · NIST NVD · CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
    Before
    not recorded
    After
    8.8 (CVSS 3.0 · NIST NVD · CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
    NIST NVD ↗
  5. Catalogue recordCVE added to the BlackTree catalogue.
    CNA ↗
Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2017-16377 · cve.blacktree.nl