ZeroHour

CVE-2014-0496

KEVmass

Use-After-Free in Adobe Reader and Acrobat Enables Code Execution

CISA: Adobe Reader and Acrobat Use-After-Free Vulnerability

CVSS
EPSS
40%p99
Published
KEV added
AI analysis

Adobe Reader and Acrobat contain a use-after-free vulnerability (CWE-399) in which an object is freed from memory while still in use, potentially allowing arbitrary code execution. An attacker who gets a user to open a specially crafted PDF — typically delivered via email or the web — can gain code execution in the context of the current user. Anyone running affected versions of Adobe Reader or Acrobat, among the world's most widely deployed PDF applications, is affected. CVSS has not yet been scored, but the flaw carries a high EPSS of 40.2% over 30 days (99th percentile) and was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, confirming in-the-wild exploitation; ransomware use is unknown and no public proof-of-concept is known.

What to do: Apply Adobe's updates per vendor instructions: upgrade all Reader and Acrobat deployments to a currently supported, fully patched release, as the vendor shipped the fix in 2014. Audit endpoints for legacy, out-of-support Reader/Acrobat builds from the 9.x/10.x/11.x era that may never have been updated, and hunt for indicators of exploitation given the KEV listing. There is no reliable workaround short of patching, so handle untrusted PDFs with caution until all systems are updated.

Affected
Adobe Reader
Adobe Acrobat
Estimated exposure
massHundreds of millions of Adobe Reader/Acrobat installs historically (ubiquitous PDF client); unknown share still running unpatched 2014-era versions — Adobe Reader and Acrobat are among the most widely deployed desktop PDF applications in the world, with hundreds of millions of installations across enterprises and consumer systems, but the fraction still running unpatched legacy releases…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution.

CISA Known Exploited Vulnerability
Affected
Adobe Reader and Acrobat
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Reader and Acrobat
Weakness
CWE-399

In the news