PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-2978 Adobe CVE debrief

CVE-2017-2978 affects Adobe Digital Editions versions 4.5.3 and earlier. The issue is described as an exploitable buffer over-read that can lead to information disclosure, and NVD classifies it as CWE-125 with a HIGH CVSS 3.0 score of 7.5. Systems that still use affected versions should be updated using Adobe’s security guidance.

Vendor
Adobe
Product
Digital Editions
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-15
Original CVE updated
2026-05-13
Advisory published
2017-02-15
Advisory updated
2026-05-13

Who should care

Organizations and individual users running Adobe Digital Editions 4.5.3 or earlier, especially on systems that regularly open content processed by the application.

Technical summary

NVD maps CVE-2017-2978 to Adobe Digital Editions with vulnerable versions through 4.5.3 inclusive. The weakness is identified as CWE-125 (buffer over-read). The CVE description says successful exploitation could disclose information, while the NVD CVSS vector records network attackability with no privileges or user interaction and high availability impact. That combination makes this a version-specific vulnerability worth addressing wherever the product is still deployed.

Defensive priority

High for any environment with Adobe Digital Editions 4.5.3 or earlier installed; otherwise limited to legacy or archived systems that still use the affected product.

Recommended defensive actions

  • Review Adobe security advisory APSB17-05 and apply the fixed Adobe Digital Editions release or a newer version than 4.5.3.
  • Inventory endpoints to find any remaining installations of Adobe Digital Editions 4.5.3 and earlier.
  • Prioritize remediation on systems that process untrusted or externally supplied content through Adobe Digital Editions.
  • Verify remediation by checking installed application versions after patching or upgrade.
  • Track the NVD and Adobe advisory references for any clarifications to affected versions or remediation guidance.

Evidence notes

Source evidence is limited to the official NVD record and Adobe-linked references in the record. The NVD CPE criteria mark Adobe Digital Editions versions through 4.5.3 as vulnerable, and the weaknesses field lists CWE-125. The prose summary says exploitation could cause information disclosure, while the CVSS vector emphasizes availability impact; treat the vendor/NVD references as the authoritative scope for remediation.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-2978 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-2978

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-2978 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-2978

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.