peter bassill · operator
$ cve CVE-2013-3346 JSON

CVE-2013-3346 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 78.9% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-24.

Description

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS78.91% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-787
On CISA KEVyes — remediate by 2022-03-24
Public exploityes
Published2013-08-30
Last modified2026-06-16

CISA KEV

NameAdobe Reader and Acrobat Memory Corruption Vulnerability
Added2022-03-03
Due2022-03-24
Vendor / productAdobe / Reader and Acrobat
Ransomware usenone reported

Affected (2)

VendorProduct
adobeacrobat
adobeacrobat reader

Public exploits

SourceTitleDate
exploit-dbAdobe Reader ToolButton - Use-After-Free (Metasploit)2013-12-17

References

→ the Explorer  ·  watch your stack  ·  NVD