CVE-2017-2959 is a heap overflow vulnerability in Adobe Acrobat Reader, affecting versions 15.020.20042 and earlier, 15.006.30244 and earlier, and 11.0.18 and earlier, related to color profile metadata parsing. With a CVSS score of 7.8 (High), successful exploitation could lead to arbitrary code execution, requiring user interaction (UI:R) but with low attack complexity (AC:L). There is no evidence of active exploitation (KEV: No), nor are there public exploits available in Metasploit or ExploitDB, though it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.0.18CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
<= 15.006.30244CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
<= 15.020.20042CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
<= 15.006.30244CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* | ||
<= 15.020.20042CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.