CVE-2017-3113: Use After Free
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in JavaScript engine when creating large strings. Successful exploitation could lead to arbitrary code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3113?
CVE-2017-3113 is considered a critical vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2017-3113?
To fix CVE-2017-3113, update Adobe Acrobat and Adobe Acrobat Reader to the latest version that addresses this vulnerability.
What versions of Adobe Acrobat are affected by CVE-2017-3113?
CVE-2017-3113 affects Adobe Acrobat Reader 2017.009.20058 and earlier, Adobe Acrobat DC versions below 17.012.20098, and Acrobat 11.0.20 and earlier.
What types of exploits can occur with CVE-2017-3113?
Successful exploitation of CVE-2017-3113 can lead to arbitrary code execution, potentially allowing attackers to take control of the affected system.
Is there a workaround for CVE-2017-3113?
Currently, the best mitigation for CVE-2017-3113 is to promptly update to the patched versions of Adobe Acrobat and Reader.