First published: Fri Aug 11 2017(Updated: )
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in the JPEG parser. Successful exploitation could lead to arbitrary code execution.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | >=11.0.0<=11.0.20 | |
Adobe Acrobat Reader | >=17.011.00000<=17.011.30066 | |
Adobe Acrobat Reader DC | >=15.006.30060<=15.006.30306 | |
Adobe Acrobat Reader DC | >=15.007.20033<=17.009.20058 | |
Adobe Acrobat Reader Notification Manager | >=17.011.00000<=17.011.30066 | |
Adobe Acrobat Reader | >=15.006.30060<=15.006.30306 | |
Adobe Acrobat Reader | >=15.007.20033<=17.009.20058 | |
Adobe Acrobat Reader | >=11.0.0<=11.0.20 | |
Apple iOS and macOS | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11211 has a critical severity rating due to its potential for arbitrary code execution.
To fix CVE-2017-11211, update Adobe Acrobat Reader to the latest version available that is not vulnerable.
CVE-2017-11211 affects Adobe Acrobat Reader versions prior to 2017.009.20058 and other specified earlier versions.
Exploitation of CVE-2017-11211 could allow an attacker to execute arbitrary code on the victim's machine.
CVE-2017-11211 affects various versions of Adobe Acrobat and Adobe Acrobat Reader, including both classic and continuous release models.