ZeroHour

CVE-2010-2883

KEVmass

Stack-Based Buffer Overflow in Adobe Acrobat and Reader Allows RCE

CISA: Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability

CVSS
EPSS
82%p100
Published
KEV added
AI analysis

CVE-2010-2883 is a stack-based buffer overflow (CWE-119) in Adobe Acrobat and Adobe Reader that can be triggered remotely, for example by opening attacker-supplied PDF content. Successful exploitation allows a remote attacker to execute arbitrary code with the privileges of the local user, or to crash the application and cause a denial of service. Anyone running a vulnerable build of Adobe Acrobat or Reader is affected, and this flaw is one of the long-lived 'old Adobe flaws' that malware campaigns have been observed leveraging, as reflected in related reporting on an Asruex Trojan variant and the Spring Dragon APT. Exploitation status is significant for a vulnerability of this age: it is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-08, required action: apply updates per vendor instructions), EPSS assigns an 82.5% probability of exploitation within 30 days (100th percentile), and no public proof-of-concept is currently cataloged; ransomware use is unknown.

What to do: Apply vendor updates per Adobe's instructions, as required by CISA's KEV listing, and upgrade all Acrobat and Reader installations to a currently patched release. Inventory endpoints for legacy or unsupported Adobe Reader/Acrobat builds and prioritize patching for users who routinely handle untrusted PDFs. Until patched, treat unsolicited PDF attachments with caution and verify sender authenticity; no public PoC is known, but active exploitation is cataloged.

Affected
Adobe Acrobat
Adobe Reader
Estimated exposure
masshundreds of millions of desktop installs (Adobe Reader/Acrobat historically ubiquitous on enterprise and consumer systems) — Adobe Reader has historically been the dominant PDF reader across enterprise and consumer Windows desktops worldwide, putting the plausible affected population at an order of hundreds of millions of installs, and CISA's 2022 KEV addition…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

CISA Known Exploited Vulnerability
Affected
Adobe Acrobat and Reader
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Acrobat and Reader
Weakness
CWE-119

In the news