CVE-2017-11308: Adobe Acrobat

Critical severity, CVSS 9.8. EPSS: 8% chance of exploitation in the next 30 days.

Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Affected products

  • Adobe Acrobat: from 11.0.0, up to and including 11.0.22; from 17.011.30066, before 17.011.30068 (fixed in 17.011.30068)
  • Adobe Acrobat DC: from 15.006.30355, before 15.006.30392 (fixed in 15.006.30392); from 17.012.20098, before 18.009.20044 (fixed in 18.009.20044)
  • Adobe Acrobat Reader: from 11.0.0, up to and including 11.0.22; from 17.011.30066, before 17.011.30068 (fixed in 17.011.30068)
  • Adobe Acrobat Reader DC: from 15.006.30355, before 15.006.30392 (fixed in 15.006.30392); from 17.012.20098, before 18.009.20044 (fixed in 18.009.20044)

Published 2018-05-19. Last modified 2026-06-17.