SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-9150

Race condition in the MoveFileEx call hook feature in Adobe Reader and Acrobat 11.x before 11.0.09 on Windows allows attackers to bypass a sandbox protection mechanism, and consequently write to files in arbitrary locations, via an NTFS junction attack,…

MEDIUM 6.4EPSS 2.27%

Does this matter?

Lower severity and a low EPSS score (2.27%). Track it; it rarely justifies an emergency change on its own.

Description

Race condition in the MoveFileEx call hook feature in Adobe Reader and Acrobat 11.x before 11.0.09 on Windows allows attackers to bypass a sandbox protection mechanism, and consequently write to files in arbitrary locations, via an NTFS junction attack, a similar issue to CVE-2014-0568.

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
EPSS
2.27% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-362
Affected
adobe/acrobat reader · adobe/acrobat
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.