VULNERABILITY INTELLIGENCE
CVE-2017-3035
CVSS score7.8 HIGH
EPSS probability4.96%
CISA KEVNot currently listed
Published2017-04-12
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable use after free vulnerability in the XML Forms Architecture (XFA) engine. Successful exploitation could lead to arbitrary code execution.
Weakness classification
- CWE-416: Use After Free
Primary references
- psirt@adobe.com
- psirt@adobe.com
- psirt@adobe.com — Vendor Advisory
- nvd@nist.gov — Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108
- af854a3a-2127-422b-91ae-364da2661108
- af854a3a-2127-422b-91ae-364da2661108 — Vendor Advisory