CVE-2011-2462
Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 86.56% probability · 100th percentile
- CISA KEV
- Listed 8 June 2022 · due 22 June 2022
- Weakness
- CWE-787
- Affected
- adobe/acrobat · adobe/acrobat reader
- Source
- psirt@adobe.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2011-2462
References
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00019.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00020.htmlBroken Link
- http://www.adobe.com/support/security/advisories/apsa11-04.htmlVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb11-30.htmlNot Applicable
- http://www.adobe.com/support/security/bulletins/apsb12-01.htmlNot Applicable
- http://www.redhat.com/support/errata/RHSA-2012-0011.htmlBroken Link
- http://www.us-cert.gov/cas/techalerts/TA11-350A.htmlThird Party Advisory, US Government Resource
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14562Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00019.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00020.htmlBroken Link
- http://www.adobe.com/support/security/advisories/apsa11-04.htmlVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb11-30.htmlNot Applicable
- http://www.adobe.com/support/security/bulletins/apsb12-01.htmlNot Applicable
- http://www.redhat.com/support/errata/RHSA-2012-0011.htmlBroken Link
- http://www.us-cert.gov/cas/techalerts/TA11-350A.htmlThird Party Advisory, US Government Resource
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14562Broken Link
- https://github.com/cisagov/vulnrichment/issues/199Issue Tracking
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-2462US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.