PatchSiren cyber security CVE debrief
CVE-2017-2980 Adobe CVE debrief
CVE-2017-2980 is a high-severity Adobe Digital Editions issue affecting version 4.5.3 and earlier. According to the NVD record, the flaw is a buffer over-read (CWE-125) and successful exploitation could result in information disclosure. The public record points to Adobe’s APSB17-05 advisory and the NVD entry for affected-version and remediation context.
- Vendor
- Adobe
- Product
- Digital Editions
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-15
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-15
- Advisory updated
- 2026-05-13
Who should care
Organizations and individuals that use or distribute Adobe Digital Editions, especially where users open untrusted or externally supplied ebook content. Security teams should also care if they maintain software inventories or endpoint baselines that include Adobe Digital Editions.
Technical summary
NVD classifies the issue as CWE-125 (buffer over-read) and rates it CVSS 3.0 7.5 HIGH with vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The affected product scope in the record is Adobe Digital Editions versions 4.5.3 and earlier. The documented impact is information disclosure, and the vendor advisory reference is APSB17-05.
Defensive priority
High for environments that still have Adobe Digital Editions 4.5.3 or earlier installed. Prioritize inventory, removal, or upgrade because the issue is public, high severity, and tied to a product that may process untrusted content.
Recommended defensive actions
- Inventory endpoints and software catalogs for Adobe Digital Editions.
- Upgrade Adobe Digital Editions to a version newer than 4.5.3, or remove the product if it is not required.
- Treat ebook files from untrusted sources as higher-risk until affected versions are eliminated.
- Validate that endpoint and application-control policies reflect the updated version baseline.
- Track Adobe advisory APSB17-05 and the NVD record for any additional remediation notes.
Evidence notes
Source corpus shows the CVE published on 2017-02-15 and modified by NVD on 2026-05-13. NVD lists Adobe Digital Editions cpe:2.3:a:adobe:digital_editions:* with vulnerable versions ending at 4.5.3, identifies CWE-125, and gives CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The only vendor-linked advisory in the supplied corpus is Adobe APSB17-05.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-2980 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-2980
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-2980 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-2980
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://helpx.adobe.com/security/products/Digital-Editions/apsb17-05.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.