Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 87.0%; technical severity is CVSS 7.8.
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as exploited in the wild in February 2013.
Who should care
- Teams operating Acrobat, Acrobat Reader, Reader and Acrobat +7 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Acrobat, Acrobat Reader, Reader and Acrobat +7 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Adobe Security advisory Apsa13 02
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Advisory
Technical details
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- CWE
- CWE-787
- Affected versions
- Adobe Acrobat (Start Including 9.0, End Excluding 9.5.4 | Start Including 10.0, End Excluding 10.1.6 | Start Including 11.0, End Excluding 11.0.02); Adobe Acrobat Reader (Start Including 10.0, End Excluding 10.1.6 | Start Including 11.0, End Excluding 11.0.02 | Start Including 9.0, End Excluding 9.5.4); Adobe Reader and Acrobat; Opensuse Opensuse (Version 11.4 | Version 12.1); Redhat Enterprise Linux Desktop (Version 6.0); Redhat Enterprise Linux Eus (Version 5.9 | Version 6.4); Redhat Enterprise Linux Server (Version 6.0); Redhat Enterprise Linux Server Aus (Version 5.9 | Version 6.4)
- Fixed versions
- Adobe Acrobat (Fixed from 9.5.4, 10.1.6, 11.0.02); Adobe Acrobat Reader (Fixed from 10.1.6, 11.0.02, 9.5.4)
- Published
- 14 February 2013
- Attack vector
- Local
- Privileges required
- None
- User interaction
- Required
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 87.0%
- Signal calculated at 82
External references
- Red Hat Third-party advisory RHSA 2013 0551
- CERT/CC Government advisory 422807
- CISA Government advisory CVE-2013-0640
- Blog Fireeye Technical reference In Turn Its Pdf Time
- Lists Opensuse Third-party advisory Msg00021
- Lists Opensuse Third-party advisory Msg00023
- Lists Opensuse Third-party advisory Msg00024
- Oval Cisecurity Technical reference Oval%3Aorg.mitre.oval%3Adef%3A16406