SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2013-2729

Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability

KEVCRITICAL 9.8EPSS 66.6%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 18 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
66.55% probability · 99th percentile
CISA KEV
Listed 28 March 2022 · due 18 April 2022
Weakness
CWE-190
Affected
adobe/acrobat · adobe/acrobat reader · suse/linux enterprise desktop · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux workstation
Source
psirt@adobe.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2013-2729

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.