CVE-2017-3034 is an integer overflow vulnerability in the XML Forms Architecture (XFA) engine of Adobe Acrobat Reader, affecting versions 11.0.19 and earlier, 15.006.30280 and earlier, and 15.023.20070 and earlier. This flaw, related to layout functionality, could allow an attacker to achieve arbitrary code execution. Rated with a CVSS score of 7.8 (High), successful exploitation requires user interaction, typically through opening a malicious PDF document. While not listed in CISA's KEV catalog, there is no public exploit code available, and community discussion and media coverage are limited, suggesting it is not widely exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.0.19CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
<= 15.006.30280CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
<= 15.023.20070CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
<= 15.006.30280CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* | ||
<= 15.023.20070CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.