Memory Corruption Vulnerability in Adobe Acrobat Reader Products
CVE-2017-3044
7.8HIGH
Key Information:
- Vendor
- Adobe
- Vendor
- CVE Published:
- 12 April 2017
Summary
Adobe Acrobat Reader suffers from a memory corruption vulnerability in its JPEG 2000 engine, particularly during image scaling operations. This flaw can enable attackers to execute arbitrary code by crafting malicious images that exploit the vulnerability, potentially compromising user systems. Users of affected versions are strongly encouraged to update to the latest releases to mitigate risk.
Affected Version(s)
Adobe Acrobat Reader 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier. Adobe Acrobat Reader 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier.
References
EPSS Score
16% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved