Use-After-Free Vulnerability in Adobe Acrobat Reader's XFA Engine
CVE-2017-2951
Key Information:
- Vendor
- Adobe
- Vendor
- CVE Published:
- 11 January 2017
Summary
A significant use-after-free vulnerability exists within the XFA engine of Adobe Acrobat Reader, specifically affecting how sub-form functionality is handled. If successfully exploited, this vulnerability may allow attackers to execute arbitrary code on the host system, potentially leading to unauthorized access and control over the affected applications. It is crucial for users and administrators to update their software to mitigate such risks, as exploiting this vulnerability can have serious security implications.
Affected Version(s)
Adobe Acrobat Reader 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier. Adobe Acrobat Reader 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved