ZeroHour

CVE-2014-0546

KEVmass

Sandbox Bypass in Adobe Reader and Acrobat on Windows

CISA: Adobe Reader and Acrobat Sandbox Bypass Vulnerability

CVSS
EPSS
22%p98
Published
KEV added
AI analysis

Adobe Reader and Acrobat on Windows contain a sandbox bypass (CVE-2014-0546) in which an attacker can defeat the application's sandbox protection mechanism and execute native code in a privileged context. The source data does not specify the exact trigger, but PDF-reader sandbox escapes are normally exploited by getting a user to process attacker-supplied PDF content and are typically chained with a PDF-parsing bug to reach full code execution outside the sandbox. Successful exploitation gives an attacker native code execution beyond the sandbox's restrictions, materially increasing the impact of any accompanying PDF exploit. Only Windows installations of Adobe Reader and Acrobat are identified as affected in the available data. The flaw is known to be exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-05-25 (ransomware use unknown), EPSS estimates a 22.3% probability of exploitation within 30 days (98th percentile), and no public proof-of-concept is known.

What to do: Inventory Windows endpoints for Adobe Reader and Acrobat and update them to the latest patched release per Adobe's security bulletin, per CISA's required action (patching is mandatory for U.S. federal agencies given the KEV listing). Because the flaw defeats the sandbox itself, there is no strong configuration-only mitigation, so patching is the primary control; prioritize endpoints that open untrusted PDFs and verify afterwards that no legacy unpatched builds remain.

Affected
Adobe Reader (Windows)
Adobe Acrobat (Windows)
Estimated exposure
massHundreds of millions of Windows users potentially exposed (Adobe Reader/Acrobat ubiquity); count of endpoints still running vulnerable legacy builds unknown,… — Adobe Reader has historically been among the most widely deployed Windows applications, with hundreds of millions of cumulative installs cited, so the plausible exposure base is at minimum tens of millions of endpoints; how many systems…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context.

CISA Known Exploited Vulnerability
Affected
Adobe Reader and Acrobat
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Reader and Acrobat

In the news