CVE-2017-11275 describes a heap overflow vulnerability in Adobe Digital Editions 4.5.4 and earlier versions. This flaw could allow an unauthenticated attacker to achieve arbitrary code execution. With a CVSS score of 7.5 (HIGH) and an EPSS score indicating higher than 93% of all CVEs, it represents a significant risk, though it does not require user interaction for exploitation. While there is no known active exploitation (KEV) or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.5.5CPE matchmatch criteria | cpe:2.3:a:adobe:digital_editions:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.