CVE-2017-11254: Use After Free
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in the Acrobat/Reader's JavaScript engine. Successful exploitation could lead to arbitrary code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11254?
CVE-2017-11254 has a high severity rating due to its potential to allow arbitrary code execution.
How do I fix CVE-2017-11254?
To fix CVE-2017-11254, users should update Adobe Acrobat Reader to the latest version available.
What products are affected by CVE-2017-11254?
CVE-2017-11254 affects various versions of Adobe Acrobat Reader and Adobe Acrobat DC, specifically those prior to the specified versions.
Can CVE-2017-11254 be exploited remotely?
Yes, CVE-2017-11254 can potentially be exploited remotely through malicious PDF documents.
What types of vulnerabilities does CVE-2017-11254 represent?
CVE-2017-11254 represents a use after free vulnerability specifically within the JavaScript engine of Adobe Acrobat Reader.