CVE-2017-11232
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability when processing Enhanced Metafile Format (EMF) data related to brush manipulation. Successful exploitation could lead to arbitrary code execution.
Affected (8)
Products: Adobe: Acrobat, Acrobat Dc, Acrobat Reader, Acrobat Reader Dc, Reader
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.0.0 to 11.0.20 | |
| From 15.006.30060 to 15.006.30306 | |
| From 17.011.00000 to 17.011.30066 | |
| From 15.006.30060 to 15.006.30306 | |
| From 11.0.0 to 11.0.20 |
| Running on/with | Platform Versions |
|---|---|
Apple Mac Os X | All versions |
Microsoft Windows | All versions |
Related CWEs
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-416
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
References (6)
Source: psirt@adobe.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.