PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-2929 Adobe CVE debrief

CVE-2017-2929 is a medium-severity DOM-based cross-site scripting issue in the Adobe Acrobat Chrome extension version 15.1.0.3 and earlier. According to NVD, successful exploitation could lead to JavaScript code execution. Adobe’s security advisory APSB17-03 is listed as the patch reference.

Vendor
Adobe
Product
Acrobat
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-24
Original CVE updated
2026-05-13
Advisory published
2017-01-24
Advisory updated
2026-05-13

Who should care

Administrators and security teams managing Chrome environments where the Adobe Acrobat Chrome extension is installed, especially if older extension versions may still be present.

Technical summary

NVD classifies this issue as CWE-79 (cross-site scripting) with CVSS 3.0 vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, score 6.1. The vulnerable CPE entry names adobe:acrobat:15.1.0.3 and earlier in the Chrome extension context. Because the flaw is DOM-based XSS, attacker-controlled input can be handled unsafely in the browser extension and may enable JavaScript execution when a user interacts with content.

Defensive priority

Medium. The issue requires user interaction and is not known here as a KEV item, but it can result in JavaScript execution in a browser-integrated Adobe component, so affected deployments should be patched or removed promptly.

Recommended defensive actions

  • Update Adobe Acrobat Chrome extension to a version newer than 15.1.0.3 using Adobe’s guidance in APSB17-03.
  • Audit managed endpoints for the affected Acrobat Chrome extension version and verify no legacy installations remain.
  • Treat untrusted content opened in the affected browser-extension workflow as potentially unsafe until remediation is confirmed.
  • Prioritize remediation in environments where users commonly open PDF-related content in Chrome with the Adobe extension enabled.

Evidence notes

The debrief is based on NVD metadata and Adobe’s referenced advisory link. NVD lists the vulnerable product scope as adobe:acrobat:15.1.0.3 and earlier and identifies CWE-79 with CVSS 3.0 AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The vendor advisory reference is https://helpx.adobe.com/security/products/acrobat/apsb17-03.html. No KEV enrichment is present in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-2929 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-2929

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-2929 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-2929

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.