CVE-2017-3116

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the MakeAccessible plugin when parsing TrueType font data. Successful exploitation could lead to arbitrary code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
adobeCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
VendorProductVersion
adobeacrobat
11.0.0 ≤
𝑥
< 11.0.21
adobeacrobat_dc
15.000.0000 ≤
𝑥
< 15.006.30355
adobeacrobat_dc
17.000.0000 ≤
𝑥
≤ 17.011.30066
adobeacrobat_dc
17.000.0000 ≤
𝑥
< 17.012.20098
adobeacrobat_reader_dc
15.000.0000 ≤
𝑥
< 15.006.30355
adobeacrobat_reader_dc
17.000.0000 ≤
𝑥
< 17.011.30066
adobeacrobat_reader_dc
17.000.0000 ≤
𝑥
< 17.012.20098
adobereader
11.0.0 ≤
𝑥
< 11.0.21
𝑥
= Vulnerable software versions