CVE-2017-3021: Adobe Acrobat

Low severity, CVSS 3.3. EPSS: 2.5% chance of exploitation in the next 30 days.

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 parser engine.

Affected products

  • Adobe Acrobat: up to and including 11.0.19
  • Adobe Acrobat DC: up to and including 15.006.30280; up to and including 15.023.20070
  • Adobe Acrobat Reader DC: up to and including 15.006.30280; up to and including 15.023.20070
  • Adobe Reader: up to and including 11.0.19

Published 2017-04-12. Last modified 2026-06-17.