CVE-2017-3009

HIGH

Adobe Acrobat < 11.0.18 - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable buffer overflow vulnerability in the JPEG2000 parser. Successful exploitation could lead to information disclosure.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/97302

Scores

CVSS v3 7.5
EPSS 0.0191
EPSS Percentile 83.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-125
Status published
Products (7)
adobe/acrobat 11.0.0 - 11.0.18
adobe/acrobat_dc 15.000.0000 - 15.006.30244
adobe/acrobat_dc 15.000.0000 - 15.020.20042
adobe/acrobat_reader_dc 15.000.0000 - 15.006.30244
adobe/acrobat_reader_dc 15.000.0000 - 15.020.20042
adobe/reader 11.0.0 - 11.0.18
n/a/Adobe Acrobat Reader 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier. Adobe Acrobat Reader 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier.
Published Mar 31, 2017
Tracked Since Feb 18, 2026