CVE-2017-11240
9.8
CRITICAL · CVSS 3.1 · EPSS 6.2% (pctl 93)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.21% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-125 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-05-19 |
| Last modified | 2026-06-17 |
Affected (6)
| Vendor | Product |
|---|---|
| adobe | acrobat |
| adobe | acrobat dc |
| adobe | acrobat reader |
| adobe | acrobat reader dc |
| apple | macos |
| microsoft | windows |
References
→ the Explorer · watch your stack · NVD