CVE-2017-2821 describes an exploitable use-after-free vulnerability in the PDF parsing functionality of Lexmark Perceptive Document Filters versions 11.3.0.2400 and 11.4.0.2452. This high-severity vulnerability (CVSS 8.8) allows an unauthenticated attacker to achieve direct code execution by enticing a user to open a specially crafted PDF document. While no public exploits (Metasploit, Nuclei, ExploitDB) are known and it's not listed in CISA's KEV catalog, there has been some community discussion, indicating awareness of the flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.3.0.2400CPE matchmatch criteria | cpe:2.3:a:lexmark:perceptive_document_filters:11.3.0.2400:*:*:*:*:*:*:* | ||
11.4.0.2452CPE matchmatch criteria | cpe:2.3:a:lexmark:perceptive_document_filters:11.4.0.2452:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.