CVE-2011-4369
Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6 on Mac OS X, Adobe Reader and Acrobat 10.x through 10.1.1 on Windows and Mac OS X, and Adobe Reader 9.x…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6 on Mac OS X, Adobe Reader and Acrobat 10.x through 10.1.1 on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 7.52% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- adobe/acrobat · adobe/acrobat reader
- Source
- psirt@adobe.com
References
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00019.html
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00020.html
- http://www.adobe.com/support/security/bulletins/apsb11-30.htmlPatch, Vendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb12-01.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2012-0011.html
- http://www.securityfocus.com/bid/51092
- http://www.us-cert.gov/cas/techalerts/TA11-350A.htmlUS Government Resource
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14865
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00019.html
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00020.html
- http://www.adobe.com/support/security/bulletins/apsb11-30.htmlPatch, Vendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb12-01.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2012-0011.html
- http://www.securityfocus.com/bid/51092
- http://www.us-cert.gov/cas/techalerts/TA11-350A.htmlUS Government Resource
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14865
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.