CVE-2017-3009: Adobe Acrobat

High severity, CVSS 7.5. EPSS: 4.4% chance of exploitation in the next 30 days.

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable buffer overflow vulnerability in the JPEG2000 parser. Successful exploitation could lead to information disclosure.

Affected products

  • Adobe Acrobat: from 11.0.0, up to and including 11.0.18
  • Adobe Acrobat DC: from 15.000.0000, up to and including 15.006.30244; from 15.000.0000, up to and including 15.020.20042
  • Adobe Acrobat Reader DC: from 15.000.0000, up to and including 15.006.30244; from 15.000.0000, up to and including 15.020.20042
  • Adobe Reader: from 11.0.0, up to and including 11.0.18

Published 2017-03-31. Last modified 2026-06-17.