CVE-2017-3115
medium
CVSS v3
6.5
CVSS v2
4.3
VIR risk
6.5
Description
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an information disclosure vulnerability when handling links in a PDF document.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@adobe.com — https://helpx.adobe.com/security/products/acrobat/apsb17-24.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| macos | not-affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| adobe | acrobat | {"startIncluding":"11.0.0","endExcluding":"11.0.21"} | 11.0.21 |
| adobe | acrobat_dc | {"startIncluding":"15.000.0000","endExcluding":"15.006.30355"} | 15.006.30355 |
| adobe | acrobat_reader_dc | {"startIncluding":"15.000.0000","endExcluding":"15.006.30355"} | 15.006.30355 |
| adobe | reader | {"startIncluding":"11.0.0","endExcluding":"11.0.21"} | 11.0.21 |
References
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.