CVE-2017-11223
HIGHAdobe Acrobat < 11.0.20 - Use After Free
Title source: ruleDescription
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in the core of the XFA engine. Successful exploitation could lead to arbitrary code execution.
References (4)
Scores
CVSS v3
8.8
EPSS
0.0507
EPSS Percentile
89.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-416
Status
draft
Affected Products (7)
adobe/acrobat
< 11.0.20
adobe/acrobat_dc
< 15.006.30306
adobe/acrobat_dc
< 17.009.20058
adobe/acrobat_reader
< 17.011.30066
adobe/acrobat_reader_dc
< 15.006.30306
adobe/acrobat_reader_dc
< 17.009.20058
adobe/reader
< 11.0.20
Timeline
Published
Aug 11, 2017
Tracked Since
Feb 18, 2026