Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 78.6%; technical severity is CVSS 9.8.
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.
Who should care
- Teams operating Acrobat, Acrobat Reader, Reader and Acrobat
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Acrobat, Acrobat Reader, Reader and Acrobat is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Adobe Security advisory APSB13-15
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-119
- Affected versions
- Adobe Acrobat (Start Including 9.0, End Excluding 9.5.5 | Start Including 10.0, End Excluding 10.1.7 | Start Including 11.0, End Excluding 11.0.03); Adobe Acrobat Reader (Start Including 9.0, End Excluding 9.5.5 | Start Including 10.0, End Excluding 10.1.7 | Start Including 11.0, End Excluding 11.0.03); Adobe Reader and Acrobat
- Fixed versions
- Adobe Acrobat (Fixed from 9.5.5, 10.1.7, 11.0.03); Adobe Acrobat Reader (Fixed from 9.5.5, 10.1.7, 11.0.03)
- Published
- 30 August 2013
- Attack vector
- Network
- Privileges required
- None
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 78.6%
- Signal calculated at 83