CVE-2017-3122 is a memory corruption vulnerability in Adobe Acrobat Reader's image conversion engine, specifically when processing Enhanced Metafile Format (EMF) data related to Bezier curves. This flaw affects multiple versions of Adobe Acrobat Reader across various platforms, including those from Apple and Microsoft. With a CVSS score of 6.5 (Medium), successful exploitation could lead to arbitrary code execution, requiring user interaction (UI:R) but with low attack complexity (AC:L). While there are no known public exploits in Metasploit, Nuclei, or ExploitDB, and it is not listed in CISA's KEV catalog, the vulnerability has garnered some community discussion and media coverage, indicating a degree of awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.0.0, < 11.0.21CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 15.000.0000, < 15.006.30355CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 17.000.0000, <= 17.011.30066CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 17.000.0000, < 17.012.20098CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 15.000.0000, < 15.006.30355CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.