Netskope Threat Labs

FILE-PDF Adobe Reader XML Metadata memory corruption attempt

IPS-SWG

1 SID: 40618

First seen
April 2022
Last seen
October 2026

Detects a PDF exploiting CVE-2016-6943, memory corruption in Adobe Reader's XML metadata handling that can allow code execution. The rule matches the compressed metadata streams that public exploits use to corrupt parser memory.