First published: Fri Aug 11 2017(Updated: )
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability when processing Enhanced Metafile Format (EMF) data related to brush manipulation. Successful exploitation could lead to arbitrary code execution.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | >=11.0.0<=11.0.20 | |
Adobe Acrobat Reader | >=17.011.00000<=17.011.30066 | |
Adobe Acrobat | >=15.006.30060<=15.006.30306 | |
Adobe Acrobat | >=15.007.20033<=17.009.20058 | |
Adobe Acrobat Reader | >=17.011.00000<=17.011.30066 | |
Adobe Acrobat Reader | >=15.006.30060<=15.006.30306 | |
Adobe Acrobat Reader | >=15.007.20033<=17.009.20058 | |
Adobe Acrobat Reader | >=11.0.0<=11.0.20 | |
Apple iOS and macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-11232 is classified as critical due to its potential for exploitation leading to arbitrary code execution.
To fix CVE-2017-11232, upgrade Adobe Acrobat Reader to version 2017.011.30066 or later, or update to the appropriate patched version for Adobe Acrobat DC.
CVE-2017-11232 is caused by a use-after-free vulnerability related to processing Enhanced Metafile Format (EMF) data during brush manipulation.
CVE-2017-11232 affects Adobe Acrobat Reader versions 2017.009.20058 and earlier, Adobe Acrobat DC versions up to 15.006.30306, and earlier versions.
Yes, CVE-2017-11232 can potentially be exploited remotely through malicious EMF files processed by vulnerable versions of Adobe Acrobat.