First published: Fri Aug 11 2017(Updated: )
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image processing engine when processing JPEG 2000 (JP2) code stream data. Successful exploitation could lead to arbitrary code execution.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | >=11.0.0<=11.0.20 | |
Adobe Acrobat Reader | >=17.011.00000<=17.011.30066 | |
Adobe Acrobat Reader DC | >=15.006.30060<=15.006.30306 | |
Adobe Acrobat Reader DC | >=15.007.20033<=17.009.20058 | |
Adobe Acrobat Reader Notification Manager | >=17.011.00000<=17.011.30066 | |
Adobe Acrobat Reader | >=15.006.30060<=15.006.30306 | |
Adobe Acrobat Reader | >=15.007.20033<=17.009.20058 | |
Adobe Acrobat Reader | >=11.0.0<=11.0.20 | |
Apple iOS and macOS | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11226 has a critical severity rating due to the potential for remote code execution.
To fix CVE-2017-11226, users should upgrade to the latest version of Adobe Acrobat or Adobe Acrobat Reader.
CVE-2017-11226 affects Adobe Acrobat Reader versions 2017.009.20058 and earlier, and Adobe Acrobat versions 11.0.20 and earlier.
Yes, CVE-2017-11226 can be exploited remotely through specially crafted JPEG 2000 images.
CVE-2017-11226 impacts Adobe Acrobat Reader, Adobe Acrobat DC, and earlier versions of these products.