Heap Overflow Vulnerability in Adobe Acrobat Reader
CVE-2017-2942

7.8HIGH

Summary

Adobe Acrobat Reader contains a heap overflow vulnerability when processing TIFF image data. This flaw allows an attacker to craft a malicious TIFF file, and upon opening this file in the affected versions of Acrobat Reader, could potentially lead to arbitrary code execution on the user's system. Users are advised to update to the latest versions to mitigate the risk associated with this vulnerability.

Affected Version(s)

Adobe Acrobat Reader 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier. Adobe Acrobat Reader 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.