ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

Adobe’s First Patch Tuesday of 2014

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2014-0496
Use-After-Free in Adobe Reader and Acrobat Enables Code Execution

Adobe Reader and Acrobat contain a use-after-free vulnerability (CWE-399) in which an object is freed from memory while still in use, potentially allowing arbitrary code execution. An attacker who gets a user to open a specially crafted PDF — typically delivered via email or the web — can gain code execution in the context of the current user. Anyone running affected versions of Adobe Reader or Acrobat, among the world's most widely deployed PDF applications, is affected. CVSS has not yet been scored, but the flaw carries a high EPSS of 40.2% over 30 days (99th percentile) and was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, confirming in-the-wild exploitation; ransomware use is unknown and no public proof-of-concept is known.

Do: Apply Adobe's updates per vendor instructions: upgrade all Reader and Acrobat deployments to a currently supported, fully patched release, as the vendor shipped the fix in 2014. Audit endpoints for legacy, out-of-support Reader/Acrobat builds from the 9.x/10.x/11.x era that may never have been updated, and hunt for indicators of exploitation given the KEV listing. There is no reliable workaround short of patching, so handle untrusted PDFs with caution until all systems are updated.

40% KEV
  • Adobe Reader
  • Adobe Acrobat
massHundreds of millions of Adobe Reader/Acrobat installs historically (ubiquitous PDF client); unknown share still running unpatched 2014-era versions
Full article197 words · extracted from securelist.com · click to collapse

Software

Software

14 Jan 2014

minute read

This month’s Adobe Patch Tuesday release sees fixes for Flash Player, Acrobat and Reader. All vulnerabilities get the highest priority rating. This means future exploits are likely.

The Flash Player bulletin was only announced today. CVE-2014-0491 and CVE-2014-0492 both concern remote code execution vulnerabilities.

CVE-2014-0493, CVE-2014-0495 and CVE-2014-0496 affect Acrobat and Reader. These CVEs also concern remote code execution vulnerabilities. All of this month’s vulnerabilities were reported to Adobe directly.

Given the severity of the vulnerabilities we recommend applying these patches as soon as possible.

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/adobes-first-patch-tuesday-of-2014/58211/