CVE-2017-3092

CRITICAL

Adobe Digital Editions <= 4.5.4 - Uncontrolled Search Path Element in Installer Plugin

Title source: llm
STIX 2.1

Description

Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loading of editor control library functions in the installer plugin. A successful exploitation could lead to arbitrary code execution.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/99024
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038658

Scores

CVSS v3 9.8
EPSS 0.0850
EPSS Percentile 94.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-427
Status published
Products (2)
adobe/digital_editions < 4.5.4
n/a/Adobe Digital Editions 4.5.4 and earlier. Adobe Digital Editions 4.5.4 and earlier.
Published Jun 20, 2017
Tracked Since Feb 18, 2026