CVE-2017-3113: Adobe Acrobat

High severity, CVSS 8.8. EPSS: 9.4% chance of exploitation in the next 30 days.

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in JavaScript engine when creating large strings. Successful exploitation could lead to arbitrary code execution.

Affected products

  • Adobe Acrobat: from 11.0.0, before 11.0.21 (fixed in 11.0.21)
  • Adobe Acrobat DC: from 15.000.0000, before 15.006.30355 (fixed in 15.006.30355); from 17.000.0000, up to and including 17.011.30066; from 17.000.0000, before 17.012.20098 (fixed in 17.012.20098)
  • Adobe Acrobat Reader DC: from 15.000.0000, before 15.006.30355 (fixed in 15.006.30355); from 17.000.0000, before 17.011.30066 (fixed in 17.011.30066); from 17.000.0000, before 17.012.20098 (fixed in 17.012.20098)
  • Adobe Reader: from 11.0.0, before 11.0.21 (fixed in 11.0.21)

Published 2017-08-11. Last modified 2026-06-17.