CVE-2017-2952 is a buffer overflow/underflow vulnerability within the image conversion module of Adobe Acrobat Reader (versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier), specifically when parsing tags in TIFF files. This flaw affects Adobe products and, by extension, systems running on Apple and Microsoft platforms. With a CVSS score of 7.8 (HIGH), successful exploitation could lead to arbitrary code execution, requiring user interaction (UI:R) to trigger the vulnerability. While the EPSS score is low, indicating a lower likelihood of exploitation, there is currently no public exploit code available in Metasploit or ExploitDB, and it is not listed on the CISA KEV catalog. Community discussion and media coverage are minimal, suggesting limited public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.0.18CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
<= 15.006.30244CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
<= 15.020.20042CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
<= 15.006.30244CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* | ||
<= 15.020.20042CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.