First published: Sat May 19 2018(Updated: )
Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | >=11.0.0<=11.0.22 | |
Adobe Acrobat Reader DC | >=15.006.30355<15.006.30392 | |
Adobe Acrobat Reader DC | >=17.012.20098<18.009.20044 | |
Adobe Acrobat Reader Notification Manager | >=11.0.0<=11.0.22 | |
Adobe Acrobat Reader | >=15.006.30355<15.006.30392 | |
Adobe Acrobat Reader | >=17.012.20098<18.009.20044 | |
macOS | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11250 has a high severity rating due to its potential for arbitrary code execution.
To fix CVE-2017-11250, update Adobe Acrobat and Reader to the latest versions released after the vulnerabilities.
CVE-2017-11250 affects Adobe Acrobat and Reader versions prior to 2017.012.20098, 2017.011.30066, 2015.006.30355, and 11.0.22.
Yes, successful exploitation of CVE-2017-11250 can lead to arbitrary code execution in the context of the current user.
While a specific workaround for CVE-2017-11250 is not recommended, users should avoid opening untrusted PDF files until the software is updated.