CVE-2017-2939: Buffer Overflow
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability when processing a malformed cross-reference table. Successful exploitation could lead to arbitrary code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Acrobat Readerto a version that resolves this vulnerability.Fixed in 15.020.20042 - Upgrade
Upgrade
Adobe Acrobat Readerto a version that resolves this vulnerability.Fixed in 15.006.30244 - Upgrade
Upgrade
Adobe Acrobat Readerto a version that resolves this vulnerability.Fixed in 11.0.18
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2939?
CVE-2017-2939 is considered to have a critical severity level due to its potential for arbitrary code execution.
How do I fix CVE-2017-2939?
To fix CVE-2017-2939, upgrade Adobe Acrobat Reader, Adobe Acrobat DC, or Adobe Acrobat as applicable to the latest version.
Which versions of Adobe are affected by CVE-2017-2939?
CVE-2017-2939 affects Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, and 11.0.18 and earlier.
Can CVE-2017-2939 lead to data loss?
Yes, successful exploitation of CVE-2017-2939 could potentially lead to data loss due to arbitrary code execution.
Is there a workaround for CVE-2017-2939?
While the best solution is to update the software, users can also limit exposure by disabling the opening of untrusted PDFs.