Security restrictions bypass in Adobe Reader and Adobe Acrobat - CVE-2017-3118

 

Security restrictions bypass in Adobe Reader and Adobe Acrobat - CVE-2017-3118

Published: August 14, 2017


Vulnerability identifier: #VU7825
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-3118
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions.

The weakness exists due to improper access controls. A remote attacker can send a specially crafted file, trick the victim into opening it, execute malicious attachments and gain access to arbitrary data.

Successful exploitation of the vulnerability results in information disclosure.

Affected software

Adobe Reader
Adobe Acrobat

How to mitigate CVE-2017-3118

Update Acrobat DC and Acrobat Reader DC to version 2015.006.30352 or 2017.012.20093.
Update Acrobat 2017 and Acrobat Reader 2017 to version 2017.011.30059.
Update Acrobat XI and Reader XI to version 11.21.


External References

Related Security Bulletins