peter bassill · operator
$ cve CVE-2011-2462 JSON

CVE-2011-2462 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 88.5% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-22.

Description

Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS88.52% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-787
On CISA KEVyes — remediate by 2022-06-22
Public exploityes
Published2011-12-07
Last modified2026-06-16

CISA KEV

NameAdobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability
Added2022-06-08
Due2022-06-22
Vendor / productAdobe / Reader and Acrobat
Ransomware usenone reported

Affected (5)

VendorProduct
adobeacrobat
adobeacrobat reader
applemac os x
microsoftwindows
opengroupunix

Public exploits

SourceTitleDate
exploit-dbAdobe Reader - U3D Memory Corruption (Metasploit)2012-01-14

References

→ the Explorer  ·  watch your stack  ·  NVD