Vulnerability Details CVE-2017-3090
Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loading of browser related library extensions in the installer plugin. A successful exploitation could lead to arbitrary code execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.137
EPSS Ranking 93.9%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2017-3090
-
cpe:2.3:a:adobe:digital_editions:-
-
cpe:2.3:a:adobe:digital_editions:2.0.0
-
cpe:2.3:a:adobe:digital_editions:2.0.1
-
cpe:2.3:a:adobe:digital_editions:4.0.0
-
cpe:2.3:a:adobe:digital_editions:4.0.1
-
cpe:2.3:a:adobe:digital_editions:4.0.2
-
cpe:2.3:a:adobe:digital_editions:4.0.3
-
cpe:2.3:a:adobe:digital_editions:4.5.0
-
cpe:2.3:a:adobe:digital_editions:4.5.1
-
cpe:2.3:a:adobe:digital_editions:4.5.2
-
cpe:2.3:a:adobe:digital_editions:4.5.3
-
cpe:2.3:a:adobe:digital_editions:4.5.4