CVE-2013-0641
HIGH severity · CVSS 7.8 · Buffer overflow · actively exploited (CISA KEV)
7.8CVSS HIGH exploited
Actively exploited in the wild (CISA Known Exploited Vulnerabilities).
Added to KEV 2022-03-03. US federal agencies must patch by 2022-03-24.
Summary
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary code via a crafted PDF document, as exploited in the wild in February 2013.
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges requiredNone
User interactionRequired
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)32%
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products we track (3)
Recommendation
This vulnerability is being actively exploited in the wild — patch affected products urgently. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://blogs.adobe.com/psirt/2013/02/adobe-reader-and-acrobat-vulnerability-report.htmlAdvisory
- http://blog.fireeye.com/research/2013/02/in-turn-its-pdf-time.html
- http://blogs.mcafee.com/mcafee-labs/digging-into-the-sandbox-escape-technique-of-the-recent-pdf-exploit
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00021.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00023.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00024.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2013-0551.htmlAdvisory
- http://security.gentoo.org/glsa/glsa-201308-03.xmlAdvisory