CVE-2017-3041 is a memory corruption vulnerability in Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, and 15.023.20070 and earlier, specifically within the MakeAccessible plugin when parsing font data. This vulnerability carries a CVSS score of 7.8 (High), indicating that a successful exploit, requiring user interaction (UI:R) and local access (AV:L), could lead to arbitrary code execution with high impact on confidentiality, integrity, and availability. While there is no known active exploitation (KEV: No) or public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has received some community discussion and media coverage, suggesting awareness despite the lack of readily available exploit tools.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.0.19CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
<= 15.006.30280CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
<= 15.023.20070CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
<= 15.006.30280CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* | ||
<= 15.023.20070CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.