PatchSiren cyber security CVE debrief
CVE-2017-2929 Adobe CVE debrief
CVE-2017-2929 is a medium-severity DOM-based cross-site scripting issue in the Adobe Acrobat Chrome extension version 15.1.0.3 and earlier. According to NVD, successful exploitation could lead to JavaScript code execution. Adobe’s security advisory APSB17-03 is listed as the patch reference.
- Vendor
- Adobe
- Product
- Acrobat
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-24
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-24
- Advisory updated
- 2026-05-13
Who should care
Administrators and security teams managing Chrome environments where the Adobe Acrobat Chrome extension is installed, especially if older extension versions may still be present.
Technical summary
NVD classifies this issue as CWE-79 (cross-site scripting) with CVSS 3.0 vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, score 6.1. The vulnerable CPE entry names adobe:acrobat:15.1.0.3 and earlier in the Chrome extension context. Because the flaw is DOM-based XSS, attacker-controlled input can be handled unsafely in the browser extension and may enable JavaScript execution when a user interacts with content.
Defensive priority
Medium. The issue requires user interaction and is not known here as a KEV item, but it can result in JavaScript execution in a browser-integrated Adobe component, so affected deployments should be patched or removed promptly.
Recommended defensive actions
- Update Adobe Acrobat Chrome extension to a version newer than 15.1.0.3 using Adobe’s guidance in APSB17-03.
- Audit managed endpoints for the affected Acrobat Chrome extension version and verify no legacy installations remain.
- Treat untrusted content opened in the affected browser-extension workflow as potentially unsafe until remediation is confirmed.
- Prioritize remediation in environments where users commonly open PDF-related content in Chrome with the Adobe extension enabled.
Evidence notes
The debrief is based on NVD metadata and Adobe’s referenced advisory link. NVD lists the vulnerable product scope as adobe:acrobat:15.1.0.3 and earlier and identifies CWE-79 with CVSS 3.0 AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The vendor advisory reference is https://helpx.adobe.com/security/products/acrobat/apsb17-03.html. No KEV enrichment is present in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-2929 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-2929
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-2929 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-2929
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://helpx.adobe.com/security/products/acrobat/apsb17-03.html
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.