CVE-2017-2942 is a heap overflow vulnerability affecting Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, and 11.0.18 and earlier, specifically when processing TIFF image data. This vulnerability carries a high CVSS score of 7.8, indicating a significant risk where successful exploitation could lead to arbitrary code execution on affected systems, including those running on Apple and Microsoft platforms. The attack requires user interaction, typically through opening a malicious TIFF file, but has low attack complexity. While the vulnerability has garnered some media attention and community discussion, there is currently no public exploit code available in Metasploit, Nuclei, or ExploitDB, and it is not listed on the CISA KEV catalog as actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.0.18CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
<= 15.006.30244CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
<= 15.020.20042CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
<= 15.006.30244CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* | ||
<= 15.020.20042CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.