#VU4132 Security bypass in Adobe Acrobat and Adobe Reader - CVE-2017-2947

 

#VU4132 Security bypass in Adobe Acrobat and Adobe Reader - CVE-2017-2947

Published: January 10, 2017


Vulnerability identifier: #VU4132
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-2947
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Adobe Acrobat
Adobe Reader
Software vendor:
Adobe

Description

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to unspecified error when processing PDF files. A remote attacker can create a specially crafted PDF file, trick the victim into opening it and bypass certain security restrictions.

Successful exploitation of the vulnerability may lead to sensitive information disclosure.


Remediation

Install the latest version of Adobe Reader and Acrobat:
  • Acrobat DC Continuous 15.023.20053
  • Acrobat Reader DC Continuous 15.023.20053
  • Acrobat DC Classic 15.006.30279
  • Acrobat Reader DC Classic 15.006.30279
  • Acrobat XI 11.0.19
  • Reader XI 11.0.19

External links