ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

CVE-2014-0546 used in targeted attacks

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2014-0546
Sandbox Bypass in Adobe Reader and Acrobat on Windows

Adobe Reader and Acrobat on Windows contain a sandbox bypass (CVE-2014-0546) in which an attacker can defeat the application's sandbox protection mechanism and execute native code in a privileged context. The source data does not specify the exact trigger, but PDF-reader sandbox escapes are normally exploited by getting a user to process attacker-supplied PDF content and are typically chained with a PDF-parsing bug to reach full code execution outside the sandbox. Successful exploitation gives an attacker native code execution beyond the sandbox's restrictions, materially increasing the impact of any accompanying PDF exploit. Only Windows installations of Adobe Reader and Acrobat are identified as affected in the available data. The flaw is known to be exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-05-25 (ransomware use unknown), EPSS estimates a 22.3% probability of exploitation within 30 days (98th percentile), and no public proof-of-concept is known.

Do: Inventory Windows endpoints for Adobe Reader and Acrobat and update them to the latest patched release per Adobe's security bulletin, per CISA's required action (patching is mandatory for U.S. federal agencies given the KEV listing). Because the flaw defeats the sandbox itself, there is no strong configuration-only mitigation, so patching is the primary control; prioritize endpoints that open untrusted PDFs and verify afterwards that no legacy unpatched builds remain.

22% KEV
  • Adobe Reader (Windows)
  • Adobe Acrobat (Windows)
massHundreds of millions of Windows users potentially exposed (Adobe Reader/Acrobat ubiquity); count of endpoints still running vulnerable legacy builds unknown,…
Full article208 words · extracted from securelist.com · click to collapse

Research

Research

12 Aug 2014

minute read

CVE-2014-0546 used in targeted attacks.

Today Adobe released the security bulletin APSB14-19, crediting Kaspersky Lab for reporting CVE-2014-0546.

This out of band patch fixes a rather creative sandbox escape technique that we observed in a very limited number of targeted attacks.

At the moment, we are not providing any details on these attacks as the investigation is still ongoing. Although these attacks are very rare, just to stay on the safe side we recommend everyone to get the update from the Adobe site as soon as possible.

You can grab the Adobe Reader updates here.

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/cve-2014-0546-used-in-targeted-attacks-adobe-reader-update/65577/