CVE-2017-3120: Use After Free
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in the XFA parsing engine when handling certain types of internal instructions. Successful exploitation could lead to arbitrary code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3120?
CVE-2017-3120 is considered a critical vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2017-3120?
To fix CVE-2017-3120, update Adobe Acrobat Reader to the latest version available from Adobe's official site.
What versions of Adobe Acrobat are affected by CVE-2017-3120?
CVE-2017-3120 affects Adobe Acrobat Reader 2017.009.20058 and earlier, along with several other specific versions of Adobe Acrobat DC and Reader.
What type of vulnerability is CVE-2017-3120?
CVE-2017-3120 is a use-after-free vulnerability in the XFA parsing engine of Adobe Acrobat.
Can CVE-2017-3120 be exploited remotely?
Yes, CVE-2017-3120 can be exploited remotely if a user opens a maliciously crafted PDF file.