Heap Overflow Vulnerability in Adobe Acrobat Reader
CVE-2017-2942
7.8HIGH
Key Information:
- Vendor
- Adobe
- Vendor
- CVE Published:
- 11 January 2017
Summary
Adobe Acrobat Reader contains a heap overflow vulnerability when processing TIFF image data. This flaw allows an attacker to craft a malicious TIFF file, and upon opening this file in the affected versions of Acrobat Reader, could potentially lead to arbitrary code execution on the user's system. Users are advised to update to the latest versions to mitigate the risk associated with this vulnerability.
Affected Version(s)
Adobe Acrobat Reader 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier. Adobe Acrobat Reader 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved