VulnerabilityAnalyzed
CVE-2013-0640
Adobe Reader and Acrobat Memory Corruption Vulnerability
KEVHIGH 7.8EPSS 87.0%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as exploited in the wild in February 2013.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 86.98% probability · 100th percentile
- CISA KEV
- Listed 3 March 2022 · due 24 March 2022
- Weakness
- CWE-787
- Affected
- adobe/acrobat · adobe/acrobat reader · opensuse/opensuse · suse/linux enterprise desktop · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux workstation
- Source
- psirt@adobe.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2013-0640
References
- http://blog.fireeye.com/research/2013/02/in-turn-its-pdf-time.htmlBroken Link
- http://blogs.adobe.com/psirt/2013/02/adobe-reader-and-acrobat-vulnerability-report.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00021.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00023.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00024.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0551.htmlThird Party Advisory
- http://security.gentoo.org/glsa/glsa-201308-03.xmlThird Party Advisory
- http://www.adobe.com/support/security/advisories/apsa13-02.htmlVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb13-07.htmlBroken Link
- http://www.kb.cert.org/vuls/id/422807Third Party Advisory, US Government Resource
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16406Broken Link
- http://blog.fireeye.com/research/2013/02/in-turn-its-pdf-time.htmlBroken Link
- http://blogs.adobe.com/psirt/2013/02/adobe-reader-and-acrobat-vulnerability-report.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00021.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00023.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00024.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0551.htmlThird Party Advisory
- http://security.gentoo.org/glsa/glsa-201308-03.xmlThird Party Advisory
- http://www.adobe.com/support/security/advisories/apsa13-02.htmlVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb13-07.htmlBroken Link
- http://www.kb.cert.org/vuls/id/422807Third Party Advisory, US Government Resource
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16406Broken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0640US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.