CVE-2017-2966: Adobe Acrobat

High severity, CVSS 7.8. EPSS: 10.6% chance of exploitation in the next 30 days.

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability in the image conversion engine related to parsing malformed TIFF segments. Successful exploitation could lead to arbitrary code execution.

Affected products

  • Adobe Acrobat: up to and including 11.0.18
  • Adobe Acrobat DC: up to and including 15.006.30244; up to and including 15.020.20042
  • Adobe Acrobat Reader DC: up to and including 15.006.30244; up to and including 15.020.20042
  • Adobe Reader: up to and including 11.0.18

Published 2017-01-11. Last modified 2026-06-17.