CVE-2017-5034 describes a use-after-free vulnerability in PDFium, the PDF rendering engine used in Google Chrome prior to version 57.0.2987.98 on Linux and Windows. This flaw allows a remote attacker to achieve an out-of-bounds memory read by enticing a user to open a specially crafted PDF file. With a CVSS score of 8.8 (HIGH), this vulnerability has a high impact on confidentiality, integrity, and availability, requiring user interaction but with low attack complexity. While there is no known active exploitation (KEV) or publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 57.0.2987.75CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.