CVE-2017-11236

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the internal handling of UTF-16 literal strings. Successful exploitation could lead to arbitrary code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
adobeCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
VendorProductVersion
adobeacrobat
11.0.0 ≤
𝑥
≤ 11.0.20
adobeacrobat
17.011.00000 ≤
𝑥
≤ 17.011.30066
adobeacrobat_dc
15.006.30060 ≤
𝑥
≤ 15.006.30306
adobeacrobat_dc
15.007.20033 ≤
𝑥
≤ 17.009.20058
adobeacrobat_reader
17.011.00000 ≤
𝑥
≤ 17.011.30066
adobeacrobat_reader_dc
15.006.30060 ≤
𝑥
≤ 15.006.30306
adobeacrobat_reader_dc
15.007.20033 ≤
𝑥
≤ 17.009.20058
adobereader
11.0.0 ≤
𝑥
≤ 11.0.20
𝑥
= Vulnerable software versions