CVE-2017-3034
Status: ModifiedHigh (7.8)—
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable integer overflow vulnerability in the XML Forms Architecture (XFA) engine, related to layout functionality. Successful exploitation could lead to arbitrary code execution.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Base score: 7.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 5.21%
- Percentile among all scored CVEs: 92
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (4)
CWEs
- CWE-191
References
- http://www.securityfocus.com/bid/97548
- http://www.securitytracker.com/id/1038228
- https://helpx.adobe.com/security/products/acrobat/apsb17-11.html
- http://www.zerodayinitiative.com/advisories/ZDI-17-260/
- http://www.securityfocus.com/bid/97548
- http://www.securitytracker.com/id/1038228
- https://helpx.adobe.com/security/products/acrobat/apsb17-11.html
Raw JSON (NVD)
Show
{
"id": "CVE-2017-3034",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "psirt@adobe.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Adobe Acrobat Reader 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier.",
"versions": [
{
"status": "affected",
"version": "Adobe Acrobat Reader 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier."
}
]
}
]
}
],
"published": "2017-04-12T14:59:02.327",
"references": [
{
"url": "http://www.securityfocus.com/bid/97548",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "psirt@adobe.com"
},
{
"url": "http://www.securitytracker.com/id/1038228",
"source": "psirt@adobe.com"
},
{
"url": "https://helpx.adobe.com/security/products/acrobat/apsb17-11.html",
"tags": [
"Vendor Advisory"
],
"source": "psirt@adobe.com"
},
{
"url": "http://www.zerodayinitiative.com/advisories/ZDI-17-260/",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "nvd@nist.gov"
},
{
"url": "http://www.securityfocus.com/bid/97548",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1038228",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://helpx.adobe.com/security/products/acrobat/apsb17-11.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-191"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable integer overflow vulnerability in the XML Forms Architecture (XFA) engine, related to layout functionality. Successful exploitation could lead to arbitrary code execution."
},
{
"lang": "es",
"value": "Las versiones de Adobe Acrobat Reader 11.0.19 y anteriores, 15.006.30280 y anteriores, 15.023.20070 y anteriores tienen una vulnerabilidad de desbordamiento de enteros explotable en el motor XFA (XML Forms Architecture), relacionado con la funcionalidad de diseño. Una explotación exitosa podría conducir a la ejecución arbitraria de código."
}
],
"lastModified": "2026-06-17T01:17:22.570",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "920C2C98-5D86-4436-BEFF-54D9A41D43C8",
"versionEndIncluding": "11.0.19"
},
{
"criteria": "cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E065F497-3396-4F95-B19F-35628C8AA570",
"versionEndIncluding": "15.006.30280"
},
{
"criteria": "cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FAC7EE17-469A-45D6-94B1-7C84E8727A06",
"versionEndIncluding": "15.023.20070"
},
{
"criteria": "cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EF2B91EA-41D3-4054-958C-5F174D2ADDF0",
"versionEndIncluding": "15.006.30280"
},
{
"criteria": "cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2E18E48C-BDDD-4A01-91F1-C233D53C0978",
"versionEndIncluding": "15.023.20070"
},
{
"criteria": "cpe:2.3:a:adobe:reader:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E65E415E-1C3C-472E-9750-3295B65CC6F0",
"versionEndIncluding": "11.0.19"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0FF5999A-9D12-4CDD-8DE9-A89C10B2D574"
},
{
"criteria": "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2CF61F35-5905-4BA9-AD7E-7DB261D2F256"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@adobe.com"
}