CVE-2017-11232: Infoleak
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability when processing Enhanced Metafile Format (EMF) data related to brush manipulation. Successful exploitation could lead to arbitrary code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11232?
The severity of CVE-2017-11232 is classified as critical due to its potential for exploitation leading to arbitrary code execution.
How do I fix CVE-2017-11232?
To fix CVE-2017-11232, upgrade Adobe Acrobat Reader to version 2017.011.30066 or later, or update to the appropriate patched version for Adobe Acrobat DC.
What causes CVE-2017-11232?
CVE-2017-11232 is caused by a use-after-free vulnerability related to processing Enhanced Metafile Format (EMF) data during brush manipulation.
What software is affected by CVE-2017-11232?
CVE-2017-11232 affects Adobe Acrobat Reader versions 2017.009.20058 and earlier, Adobe Acrobat DC versions up to 15.006.30306, and earlier versions.
Can CVE-2017-11232 be exploited remotely?
Yes, CVE-2017-11232 can potentially be exploited remotely through malicious EMF files processed by vulnerable versions of Adobe Acrobat.