First published: Wed Apr 12 2017(Updated: )
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the image conversion engine, related to manipulation of EMF files. Successful exploitation could lead to arbitrary code execution.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | <=11.0.19 | |
Adobe Acrobat DC | <=15.006.30280 | |
Adobe Acrobat DC | <=15.023.20070 | |
Adobe Acrobat DC | <=15.006.30280 | |
Adobe Acrobat DC | <=15.023.20070 | |
Adobe Acrobat Reader | <=11.0.19 | |
macOS Yosemite | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3054 has been classified as a critical vulnerability due to its potential to allow arbitrary code execution.
The vulnerability CVE-2017-3054 can be mitigated by updating Adobe Acrobat Reader or Acrobat DC to the latest versions.
Successful exploitation of CVE-2017-3054 can lead to memory corruption and potentially malicious code execution.
Adobe Acrobat Reader versions 11.0.19 and earlier, and Acrobat DC versions up to 15.006.30280 and 15.023.20070 are affected by CVE-2017-3054.
Users of Adobe Acrobat Reader and Acrobat DC on affected versions are vulnerable to CVE-2017-3054 if they open manipulated EMF files.