CVE-2017-11235: Use After Free
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in the image conversion engine when decompressing JPEG data. Successful exploitation could lead to arbitrary code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11235?
CVE-2017-11235 is classified as a critical vulnerability that could allow arbitrary code execution.
How do I fix CVE-2017-11235?
To fix CVE-2017-11235, update Adobe Acrobat Reader and Adobe Acrobat to the latest versions provided by Adobe.
Which versions of Adobe products are affected by CVE-2017-11235?
CVE-2017-11235 affects Adobe Acrobat Reader versions 11.0.20 and earlier, as well as several other specified versions of Acrobat and Acrobat DC.
What are the risks of not addressing CVE-2017-11235?
Failing to address CVE-2017-11235 can lead to exploitation by attackers, resulting in unauthorized access and control of the affected system.
What type of vulnerability is CVE-2017-11235?
CVE-2017-11235 is a use after free vulnerability affecting the image conversion engine in Adobe Acrobat software.