Use After Free Vulnerability in Adobe Acrobat Reader
CVE-2017-3026

7.8HIGH

Summary

Adobe Acrobat Reader versions 11.0.19 and earlier, along with multiple earlier versions of 15.0, are susceptible to a use after free vulnerability. This issue arises when the software improperly handles an internal data structure. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code, potentially compromising systems that use these affected versions of Adobe Acrobat Reader.

Affected Version(s)

Adobe Acrobat Reader 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier. Adobe Acrobat Reader 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.