#VU1305 Memory corruption in Adobe InDesign and Adobe InDesign Server - CVE-2016-7886

 

#VU1305 Memory corruption in Adobe InDesign and Adobe InDesign Server - CVE-2016-7886

Published: December 14, 2016


Vulnerability identifier: #VU1305
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2016-7886
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Adobe InDesign
Adobe InDesign Server
Software vendor:
Adobe

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to boundary error. A remote attacker can execute arbitrary code on the target system via unknown attack vectors.

Successful exploitation of the vulnerability results in compromise of vulnerable system.


Remediation

Update to version 12.0.0.

External links