Insecure Library Loading in Adobe Acrobat Reader
CVE-2017-3012
7.8HIGH
Key Information:
- Vendor
- Adobe
- Vendor
- CVE Published:
- 12 April 2017
Summary
An insecure library loading vulnerability exists in the OCR plugin of Adobe Acrobat Reader that could allow an attacker to exploit the application. This flaw enables improperly configured library loading paths, potentially leading to DLL hijacking. If successfully exploited, this vulnerability could allow an attacker to execute arbitrary code on systems using affected versions of Adobe Acrobat Reader.
Affected Version(s)
Adobe Acrobat Reader 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier. Adobe Acrobat Reader 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved