CVE-2017-3009

HIGH

Adobe Acrobat < 11.0.18 - Out-of-Bounds Read

Title source: rule

Description

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable buffer overflow vulnerability in the JPEG2000 parser. Successful exploitation could lead to information disclosure.

Scores

CVSS v3 7.5
EPSS 0.0191
EPSS Percentile 83.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-125
Status draft

Affected Products (6)

adobe/acrobat < 11.0.18
adobe/acrobat_dc < 15.006.30244
adobe/acrobat_dc < 15.020.20042
adobe/acrobat_reader_dc < 15.006.30244
adobe/acrobat_reader_dc < 15.020.20042
adobe/reader < 11.0.18

Timeline

Published Mar 31, 2017
Tracked Since Feb 18, 2026