CVE-2017-3055: Adobe Acrobat

High severity, CVSS 7.8. EPSS: 14.5% chance of exploitation in the next 30 days.

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable heap overflow vulnerability in JPEG 2000 parsing of the fragment list tag. Successful exploitation could lead to arbitrary code execution.

Affected products

  • Adobe Acrobat: up to and including 11.0.19
  • Adobe Acrobat DC: up to and including 15.006.30280; up to and including 15.023.20070
  • Adobe Acrobat Reader DC: up to and including 15.006.30280; up to and including 15.023.20070
  • Adobe Reader: up to and including 11.0.19

Published 2017-04-12. Last modified 2026-06-17.