Stats
- First seen
- April 2022
- Last seen
- October 2026
Description
Detects a PDF exploiting CVE-2016-6943, memory corruption in Adobe Reader's XML metadata handling that can allow code execution. The rule matches the compressed metadata streams that public exploits use to corrupt parser memory.