ZeroHour

CVE-2013-2729

KEVmass

Integer Overflow Remote Code Execution in Adobe Reader and Acrobat

CISA: Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability

CVSS
EPSS
67%p99
Published
KEV added
AI analysis

CVE-2013-2729 is an integer overflow (numeric error, CWE-189) in Adobe Reader and Acrobat that can be triggered when the application processes specially crafted PDF content. By causing the overflow to corrupt memory, an attacker can execute arbitrary code with the privileges of the user running Reader or Acrobat. Any user or organization running an affected version of Adobe Reader or Acrobat is exposed; the source data does not specify exact affected version ranges, and no CVSS score is available in this dataset. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-28 (ransomware use unknown), EPSS estimates a 66.6% probability of exploitation within 30 days (99th percentile), and no public proof-of-concept is known.

What to do: Apply updates for Adobe Reader and Acrobat per vendor instructions (the CISA KEV required action); because the flaw dates to 2013, any currently supported Adobe Acrobat/Reader release should already include the fix, so prioritize identifying and updating legacy Reader/Acrobat installations on user endpoints. Until patched, mitigate by using the reader's sandboxed/protected viewing mode and cautioning users against opening PDFs from untrusted sources.

Affected
Adobe Reader
Adobe Acrobat
Estimated exposure
massUnknown precisely; historically hundreds of millions of Adobe Reader/Acrobat installations, though the number of systems still running vulnerable versions… — Adobe Reader and Acrobat were the dominant desktop PDF applications with hundreds of millions of installations at the time of the 2013 disclosure, and CISA's 2022 KEV listing implies some vulnerable deployments remain, but no current…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.

CISA Known Exploited Vulnerability
Affected
Adobe Reader and Acrobat
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Reader and Acrobat
Weakness
CWE-189

In the news