CVE-2014-0496
KEVmassUse-After-Free in Adobe Reader and Acrobat Enables Code Execution
CISA: Adobe Reader and Acrobat Use-After-Free Vulnerability
Adobe Reader and Acrobat contain a use-after-free vulnerability (CWE-399) in which an object is freed from memory while still in use, potentially allowing arbitrary code execution. An attacker who gets a user to open a specially crafted PDF — typically delivered via email or the web — can gain code execution in the context of the current user. Anyone running affected versions of Adobe Reader or Acrobat, among the world's most widely deployed PDF applications, is affected. CVSS has not yet been scored, but the flaw carries a high EPSS of 40.2% over 30 days (99th percentile) and was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, confirming in-the-wild exploitation; ransomware use is unknown and no public proof-of-concept is known.
What to do: Apply Adobe's updates per vendor instructions: upgrade all Reader and Acrobat deployments to a currently supported, fully patched release, as the vendor shipped the fix in 2014. Audit endpoints for legacy, out-of-support Reader/Acrobat builds from the 9.x/10.x/11.x era that may never have been updated, and hunt for indicators of exploitation given the KEV listing. There is no reliable workaround short of patching, so handle untrusted PDFs with caution until all systems are updated.
| Adobe Reader | — |
| Adobe Acrobat | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution.
- Affected
- Adobe Reader and Acrobat
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Adobe
- Products
- Reader and Acrobat
- Weakness
- CWE-399