CVE-2017-11260 is a critical memory corruption vulnerability affecting multiple versions of Adobe Acrobat Reader, including 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier. This flaw resides in the image conversion engine when processing Enhanced Metafile Format (EMF) private data interpreted as a GIF image. With a CVSS score of 8.8 (High), successful exploitation could lead to arbitrary code execution, requiring user interaction (UI:R) but with low attack complexity (AC:L) over a network (AV:N). While no public exploit code (Metasploit, Nuclei, ExploitDB) is readily available and it's not listed in CISA's KEV catalog, its high FAUCET Risk Score of 82/100 and mention in community discussions and media coverage indicate its significance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.0.0, <= 11.0.20CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 17.011.00000, <= 17.011.30066CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 15.006.30060, <= 15.006.30306CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 15.007.20033, <= 17.009.20058CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 17.011.00000, <= 17.011.30066CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.