CVE-2017-11230

Description

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the JPEG 2000 engine. Successful exploitation could lead to arbitrary code execution.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
12.506

Associated Vulnerability

VulnerabilityOS Platform
Update Adobe Reader 11.0.20 to latest versionWindows
Multiple vulnerabilities affected in Acrobat DC 17.009.20058Windows
Multiple vulnerabilities affected in Acrobat Reader 17.008.30051Windows
Multiple vulnerabilities fixed in Adobe Acrobat DC Pro and Standard (Classic Track) update - All languages (15.006.30355)Windows
Multiple vulnerabilities fixed in Adobe Acrobat Reader MUI DC (Classic Track) update - All languages (15.006.30355)Windows
Multiple vulnerabilities fixed in Adobe Reader 11.0.21 update - All languages (APSB17-24)Windows
Multiple vulnerabilities fixed in Adobe Reader 11.0.20 update - Multilingual (MUI) installer (11.0.21)Windows
Multiple vulnerabilities fixed in Acrobat Reader 2017 2017.011.30066Windows
Multiple vulnerabilities fixed in Adobe Acrobat Reader DC (Continuous Track) update - All languages (17.012.20098)Windows
Multiple vulnerabilities fixed in Adobe Acrobat Reader MUI DC (Continuous Track) update - All languages (17.012.20098)Windows
Multiple vulnerabilities fixed in Adobe Acrobat DC Pro and Standard (Continuous Track) update - All languages (17.012.20098)Windows
Multiple vulnerabilities are fixed in Adobe Reader Update For Mac (11.0.21)Mac
Multiple Vulnerabilities are affected in Adobe Acrobat DC for MAC 15.006.30306Mac
Multiple Vulnerabilities are affected in Adobe Acrobat Reader DC for MAC 17.009.20058Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-306675Adobe Reader 11.0.23 update - All languages (APSB17-36)
PATCH-343119Adobe Acrobat DC Pro and Standard (Continuous Track) update - All languages (24.004.20272)
PATCH-315465Adobe Acrobat Reader MUI DC (Classic Track) update - All languages (15.006.30527) (APSB20-48)
PATCH-306325Adobe Acrobat DC Pro and Standard (Classic Track) update - All languages (15.006.30355)
PATCH-306326Adobe Acrobat Reader MUI DC (Classic Track) update - All languages (15.006.30355)
PATCH-306207Adobe Reader 11.0.21 update - All languages (APSB17-24)
PATCH-306211Adobe Reader 11.0.20 update - Multilingual (MUI) installer (11.0.21)
PATCH-313395Adobe Acrobat Reader 2017 MUI (Classic Track) (17.011.30166) (APSB20-13)
PATCH-306324Adobe Acrobat Reader MUI DC (Continuous Track) update - All languages (17.012.20098)
PATCH-306322Adobe Acrobat DC Pro and Standard (Continuous Track) update - All languages (17.012.20098)
PATCH-601329Adobe Reader Update For Mac (11.0.23) -APSB17-36
PATCH-611991Adobe Acrobat DC for MAC (25.001.20693)(Deployment-Only)
PATCH-611989Adobe Acrobat Reader DC for MAC (25.001.20693)(Deployment-Only)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234