First published: Sat May 19 2018(Updated: )
Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | >=11.0.0<=11.0.22 | |
Adobe Acrobat DC | >=15.006.30355<15.006.30392 | |
Adobe Acrobat DC | >=17.012.20098<18.009.20044 | |
Adobe Acrobat Reader | >=11.0.0<=11.0.22 | |
Adobe Acrobat DC | >=15.006.30355<15.006.30392 | |
Adobe Acrobat DC | >=17.012.20098<18.009.20044 | |
Apple macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-11253 is classified as critical due to its potential for arbitrary code execution.
To fix CVE-2017-11253, you should update Adobe Acrobat or Reader to the latest available version.
CVE-2017-11253 affects Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, and 11.0.22 and earlier.
The risks associated with CVE-2017-11253 include arbitrary code execution in the context of the current user, which can compromise system security.
Yes, CVE-2017-11253 can be exploited through an out-of-bounds read vulnerability in Adobe Acrobat and Reader.