Stats
- First seen
- August 2022
- Last seen
- October 2026
Description
Detects a PDF exploiting CVE-2016-4201 and CVE-2016-4205, memory corruption in Adobe Acrobat Reader's embedded font parsing that can allow code execution. The rule matches the malformed font tables that public exploits use to corrupt parser memory.