ZeroHour

CVE-2013-0640

KEVmass

Memory Corruption RCE in Adobe Reader and Acrobat (acroform.dll)

CISA: Adobe Reader and Acrobat Memory Corruption Vulnerability

CVSS
EPSS
87%p100
Published
KEV added
AI analysis

CVE-2013-0640 is a memory corruption flaw (out-of-bounds write, CWE-787) in acroform.dll, the AcroForm PDF-forms component of Adobe Reader and Acrobat, which can be triggered by opening a specially crafted PDF. An attacker who tricks a user into opening a malicious PDF gains remote code execution with the privileges of the logged-on user; this was the vector used by the MiniDuke espionage campaign of February 2013, which delivered a small government-grade backdoor assembler backdoor via PDF 0-day exploits. Anyone running unpatched Adobe Reader or Acrobat is affected, and F-Secure's discovery of in-the-wild MiniDuke samples plus Uyghur- and Tibetan-themed PDF attacks confirm active targeted exploitation. The bug carries a very high likelihood of exploitation (EPSS 87%, 100th percentile), was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03 with required action to apply vendor updates; no public PoC is catalogued, but in-the-wild exploitation is confirmed.

What to do: Apply updates per vendor instructions (the CISA KEV required action): bring all Adobe Reader and Acrobat installations to the latest patched release issued by Adobe in February 2013 or later. Inventory endpoints for outdated PDF readers, block or inspect PDFs from untrusted sources as an interim mitigation, and check government/NGO-type targeted machines for MiniDuke-style PDF-borne backdoor indicators.

Affected
Adobe Reader
Adobe Acrobat
Estimated exposure
masshundreds of millions of users (Adobe Reader/Acrobat is near-universal on desktops) — Adobe Reader is one of the most widely installed desktop applications and PDF handling is effectively universal on endpoints, so the installed base plausibly affected runs to hundreds of millions of users.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution.

CISA Known Exploited Vulnerability
Affected
Adobe Reader and Acrobat
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Reader and Acrobat
Weakness
CWE-787

In the news