CVE-2017-3090
Status: ModifiedCritical (9.8)—
Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loading of browser related library extensions in the installer plugin. A successful exploitation could lead to arbitrary code execution.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Base score: 9.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 8.50%
- Percentile among all scored CVEs: 95
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-427
References
- http://www.securityfocus.com/bid/99024
- http://www.securitytracker.com/id/1038658
- https://helpx.adobe.com/security/products/Digital-Editions/apsb17-20.html
- http://www.securityfocus.com/bid/99024
- http://www.securitytracker.com/id/1038658
- https://helpx.adobe.com/security/products/Digital-Editions/apsb17-20.html
Raw JSON (NVD)
Show
{
"id": "CVE-2017-3090",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "psirt@adobe.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Adobe Digital Editions 4.5.4 and earlier.",
"versions": [
{
"status": "affected",
"version": "Adobe Digital Editions 4.5.4 and earlier."
}
]
}
]
}
],
"published": "2017-06-20T17:29:00.567",
"references": [
{
"url": "http://www.securityfocus.com/bid/99024",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "psirt@adobe.com"
},
{
"url": "http://www.securitytracker.com/id/1038658",
"source": "psirt@adobe.com"
},
{
"url": "https://helpx.adobe.com/security/products/Digital-Editions/apsb17-20.html",
"tags": [
"Vendor Advisory"
],
"source": "psirt@adobe.com"
},
{
"url": "http://www.securityfocus.com/bid/99024",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1038658",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://helpx.adobe.com/security/products/Digital-Editions/apsb17-20.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-427"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loading of browser related library extensions in the installer plugin. A successful exploitation could lead to arbitrary code execution."
},
{
"lang": "es",
"value": "Adobe Digital Editions versiones 4.5.4 y anteriores contienen una vulnerabilidad de carga de librería insegura. La vulnerabilidad se debe a la carga insegura de la biblioteca de extensiones de biblioteca relacionadas con el navegador en el complemento de instalación. Una explotación exitosa podría conducir a la ejecución de código arbitrario."
}
],
"lastModified": "2026-06-17T01:17:29.667",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adobe:digital_editions:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "52633641-DC5F-435B-81F0-62EE1D380999",
"versionEndIncluding": "4.5.4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@adobe.com"
}