First published: Fri Aug 11 2017(Updated: )
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has a security bypass vulnerability related to execution of malicious attachments.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | >=11.0.0<11.0.21 | |
Adobe Acrobat | >=15.000.0000<15.006.30355 | |
Adobe Acrobat | >=17.000.0000<=17.011.30066 | |
Adobe Acrobat | >=17.000.0000<17.012.20098 | |
Adobe Acrobat Reader | >=15.000.0000<15.006.30355 | |
Adobe Acrobat Reader | >=17.000.0000<17.011.30066 | |
Adobe Acrobat Reader | >=17.000.0000<17.012.20098 | |
Adobe Acrobat Reader | >=11.0.0<11.0.21 | |
Apple iOS and macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3118 is classified as a critical security bypass vulnerability that can lead to the execution of malicious attachments.
To mitigate CVE-2017-3118, users should update Adobe Acrobat Reader and Adobe Acrobat DC to the latest versions released after the affected versions.
Adobe Acrobat Reader versions 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier are affected by CVE-2017-3118.
CVE-2017-3118 primarily affects Adobe Acrobat software and does not involve operating system-specific vulnerabilities.
CVE-2017-3118 can allow attackers to execute malicious attachments without proper user consent or awareness, posing a significant security risk.