CVE-2017-2962
HIGHAdobe Acrobat Reader <15.020.20042, <15.006.30244, <11.0.18 - RCE
Title source: llmDescription
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable type confusion vulnerability in the XSLT engine related to localization functionality. Successful exploitation could lead to arbitrary code execution.
References (4)
Scores
CVSS v3
7.8
EPSS
0.0548
EPSS Percentile
90.1%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-704
Status
draft
Affected Products (6)
adobe/acrobat
< 11.0.18
adobe/acrobat_dc
< 15.006.30244
adobe/acrobat_dc
< 15.020.20042
adobe/acrobat_reader_dc
< 15.006.30244
adobe/acrobat_reader_dc
< 15.020.20042
adobe/reader
< 11.0.18
Timeline
Published
Jan 11, 2017
Tracked Since
Feb 18, 2026