cbcvebase.
CVE-2017-11221
published 2017-08-11

CVE-2017-11221: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable type…

PriorityP349high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
8.87%
94.7th percentile
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable type confusion vulnerability in the annotation functionality. Successful exploitation could lead to arbitrary code execution.

Affected

12 ranges
VendorProductVersion rangeFixed in
adobeacrobat11.0.0 – 11.0.20
adobeacrobat17.011.00000 – 17.011.30066
adobeacrobat_dc15.006.30060 – 15.006.30306
adobeacrobat_dc15.007.20033 – 17.009.20058
adobeacrobat_reader17.011.00000 – 17.011.30066
adobeacrobat_reader_dc15.006.30060 – 15.006.30306
adobeacrobat_reader_dc15.007.20033 – 17.009.20058
adobereader11.0.0 – 11.0.20
adobe_systems_incorporatedacrobat_reader
adobe_systems_incorporatedacrobat_reader
adobe_systems_incorporatedacrobat_reader
adobe_systems_incorporatedacrobat_reader

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.