CVE-2017-2947Improper Input Validation in Adobe Acrobat

Severity
5.5MEDIUMNVD
EPSS
2.5%
top 14.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 11
Latest updateMay 17

Description

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have a security bypass vulnerability when manipulating Form Data Format (FDF).

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDadobe/acrobat_reader_dc15.006.30244+1
NVDadobe/reader11.0.18
NVDadobe/acrobat11.0.18
NVDadobe/acrobat_dc15.006.30244+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-68m5-j845-c5j8: Adobe Acrobat Reader versions 152022-05-17
CVEList
CVE-2017-2947: Adobe Acrobat Reader versions 152017-01-11
CVE-2017-2947 — Improper Input Validation in Adobe | cvebase