ZeroHour

CVE-2011-2462

KEVmass

U3D Memory Corruption in Adobe Reader and Acrobat Enables Remote Code Execution

CISA: Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability

CVSS
EPSS
87%p100
Published
KEV added
AI analysis

CVE-2011-2462 is an out-of-bounds write (CWE-787) memory corruption flaw in the Universal 3D (U3D) component of Adobe Reader and Acrobat. An attacker triggers it by convincing a user to open a specially crafted PDF containing embedded 3D (U3D) content, which corrupts memory when the component parses the 3D data. Successful exploitation can yield remote code execution with the privileges of the logged-in user, or a denial of service if it merely crashes the application. Anyone running an affected Adobe Reader or Acrobat release is exposed, though the source data does not specify the affected version ranges. The flaw is confirmed exploited in the wild — CISA added it to the KEV catalog on 2022-06-08 (ransomware use: unknown) — and EPSS assigns it an 86.6% probability of exploitation within 30 days (100th percentile).

What to do: Apply Adobe Reader/Acrobat updates per vendor instructions as required by the CISA KEV listing, prioritizing legacy or unpatched installations, and verify installed versions against Adobe's U3D security advisory. Until patched, treat PDFs from untrusted sources — especially PDFs with embedded 3D/U3D content — as suspect and avoid opening them in Reader/Acrobat. Because the flaw dates to 2011, any environment still running unpatched legacy versions should be patched or upgraded promptly.

Affected
Adobe Reader and Acrobat (Universal 3D component)
Estimated exposure
mass≈ hundreds of millions of desktops running Adobe Reader/Acrobat (Reader has historically been near-ubiquitous on business and consumer PCs) — Adobe Reader/Acrobat's near-ubiquitous deployment across enterprise and consumer desktops (historically hundreds of millions of installs) implies mass exposure, though only unpatched legacy versions carrying the vulnerable U3D component…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS).

CISA Known Exploited Vulnerability
Affected
Adobe Reader and Acrobat
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Reader and Acrobat
Weakness
CWE-787

In the news