First published: Fri Aug 11 2017(Updated: )
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in JavaScript engine when creating large strings. Successful exploitation could lead to arbitrary code execution.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | >=11.0.0<11.0.21 | |
Adobe Acrobat Reader DC | >=15.000.0000<15.006.30355 | |
Adobe Acrobat Reader DC | >=17.000.0000<=17.011.30066 | |
Adobe Acrobat Reader DC | >=17.000.0000<17.012.20098 | |
Adobe Acrobat Reader | >=15.000.0000<15.006.30355 | |
Adobe Acrobat Reader | >=17.000.0000<17.011.30066 | |
Adobe Acrobat Reader | >=17.000.0000<17.012.20098 | |
Adobe Acrobat Reader | >=11.0.0<11.0.21 | |
Apple iOS and macOS | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3113 is considered a critical vulnerability due to the potential for arbitrary code execution.
To fix CVE-2017-3113, update Adobe Acrobat and Adobe Acrobat Reader to the latest version that addresses this vulnerability.
CVE-2017-3113 affects Adobe Acrobat Reader 2017.009.20058 and earlier, Adobe Acrobat DC versions below 17.012.20098, and Acrobat 11.0.20 and earlier.
Successful exploitation of CVE-2017-3113 can lead to arbitrary code execution, potentially allowing attackers to take control of the affected system.
Currently, the best mitigation for CVE-2017-3113 is to promptly update to the patched versions of Adobe Acrobat and Reader.