PatchSiren cyber security CVE debrief
CVE-2017-2978 Adobe CVE debrief
CVE-2017-2978 affects Adobe Digital Editions versions 4.5.3 and earlier. The issue is described as an exploitable buffer over-read that can lead to information disclosure, and NVD classifies it as CWE-125 with a HIGH CVSS 3.0 score of 7.5. Systems that still use affected versions should be updated using Adobe’s security guidance.
- Vendor
- Adobe
- Product
- Digital Editions
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-15
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-15
- Advisory updated
- 2026-05-13
Who should care
Organizations and individual users running Adobe Digital Editions 4.5.3 or earlier, especially on systems that regularly open content processed by the application.
Technical summary
NVD maps CVE-2017-2978 to Adobe Digital Editions with vulnerable versions through 4.5.3 inclusive. The weakness is identified as CWE-125 (buffer over-read). The CVE description says successful exploitation could disclose information, while the NVD CVSS vector records network attackability with no privileges or user interaction and high availability impact. That combination makes this a version-specific vulnerability worth addressing wherever the product is still deployed.
Defensive priority
High for any environment with Adobe Digital Editions 4.5.3 or earlier installed; otherwise limited to legacy or archived systems that still use the affected product.
Recommended defensive actions
- Review Adobe security advisory APSB17-05 and apply the fixed Adobe Digital Editions release or a newer version than 4.5.3.
- Inventory endpoints to find any remaining installations of Adobe Digital Editions 4.5.3 and earlier.
- Prioritize remediation on systems that process untrusted or externally supplied content through Adobe Digital Editions.
- Verify remediation by checking installed application versions after patching or upgrade.
- Track the NVD and Adobe advisory references for any clarifications to affected versions or remediation guidance.
Evidence notes
Source evidence is limited to the official NVD record and Adobe-linked references in the record. The NVD CPE criteria mark Adobe Digital Editions versions through 4.5.3 as vulnerable, and the weaknesses field lists CWE-125. The prose summary says exploitation could cause information disclosure, while the CVSS vector emphasizes availability impact; treat the vendor/NVD references as the authoritative scope for remediation.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-2978 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-2978
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-2978 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-2978
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://helpx.adobe.com/security/products/Digital-Editions/apsb17-05.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.