cbcvebase.
CVE-2017-3117
published 2017-08-11

CVE-2017-3117: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap…

PriorityP355high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
18.89%
97.0th percentile
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in the plugin that handles links within the PDF. Successful exploitation could lead to arbitrary code execution.

Affected

12 ranges
VendorProductVersion rangeFixed in
adobeacrobat>= 11.0.0 < 11.0.2111.0.21
adobeacrobat_dc>= 15.000.0000 < 15.006.3035515.006.30355
adobeacrobat_dc>= 17.000.0000 < 17.012.2009817.012.20098
adobeacrobat_dc17.000.0000 – 17.011.30066
adobeacrobat_reader_dc>= 15.000.0000 < 15.006.3035515.006.30355
adobeacrobat_reader_dc>= 17.000.0000 < 17.011.3006617.011.30066
adobeacrobat_reader_dc>= 17.000.0000 < 17.012.2009817.012.20098
adobereader>= 11.0.0 < 11.0.2111.0.21
adobe_systems_incorporatedacrobat_reader
adobe_systems_incorporatedacrobat_reader
adobe_systems_incorporatedacrobat_reader
adobe_systems_incorporatedacrobat_reader

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.