CVE-2016-6938

critical
Published 2016-09-17 · Modified 2026-05-06
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
10.0
VIR risk
9.8

Description

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4255.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@adobe.com — https://helpx.adobe.com/security/products/acrobat/apsb16-26.html

OS impact

OSVersionStatusFixed in
macos macosnot-affected

Application impact

VendorProductVersionsFixed
adobe adobeacrobat{"endIncluding":"11.0.16"}
adobe adobeacrobat_dc{"endIncluding":"15.006.30174"}
adobe adobeacrobat_reader_dc{"endIncluding":"15.006.30174"}
adobe adobereader{"endIncluding":"11.0.16"}

References

CWEs

CWE-416

Verify integrity in audit chain (admin only). AS-IS.