⚠ Actively exploited
Added to CISA KEV on 2022-06-08. Federal agencies required to patch by 2022-06-22. Required action: Apply updates per vendor instructions..
Severity
9.8CRITICALNVD
NVD9.3NVD7.8NVD6.2NVD4.3
EPSS
70.8%
top 1.29%
CISA KEV
KEV
Added 2022-06-08
Due 2022-06-22
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedFeb 7
KEV addedJun 8
KEV dueJun 22
CISA Required Action: Apply updates per vendor instructions.

Description

Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDadobe/acrobat_reader< 8.1.2+1
NVDadobe/acrobat< 8.1.2+1

Patches

🔴Vulnerability Details

6
GHSA
GHSA-vh44-jfrh-jf4g: Adobe Reader and Acrobat 82022-05-01
GHSA
GHSA-xjr9-phw2-2wjx: Multiple buffer overflows in Adobe Reader and Acrobat 82022-05-01
GHSA
GHSA-f6hj-jcpc-rwr6: Untrusted search path vulnerability in Adobe Reader and Acrobat 82022-05-01
GHSA
GHSA-r5pf-wcfw-339x: The DOC2022-05-01
GHSA
GHSA-qw37-hh98-8g3j: Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 82022-05-01

📋Vendor Advisories

6
CISA
Adobe Acrobat and Reader Unspecified Vulnerability2022-06-08
Red Hat
acroread: silent print vulnerability2008-02-08
Red Hat
acroread JavaScript Insecure Method Exposure2008-02-08
Red Hat
acroread JavaScript Insecure Libary Search Path2008-02-08
Red Hat
acroread Multiple buffer overflows2008-02-08

🕵️Threat Intelligence

2
Krebs
iPack Exploit Kit Bites Windows Users2010-04-16
Krebs
iPack Exploit Kit Bites Windows Users &#8211; Krebs on Security2010-04-01

📄Research Papers

1
arXiv
Towards Adversarial Malware Detection: Lessons Learned from PDF-based Attacks2020-04-14

💬Community

5
Bugzilla
CVE-2007-5663 acroread JavaScript Insecure Method Exposure2008-02-13
Bugzilla
CVE-2007-5666 acroread JavaScript Insecure Libary Search Path2008-02-13
Bugzilla
CVE-2007-5659 acroread Multiple buffer overflows2008-02-13
Bugzilla
CVE-2008-0667 acroread: silent print vulnerability2008-02-12
Bugzilla
CVE-2008-0655 acroread: unspecified vulnerabilities2008-02-08
CVE-2008-0655 — Sensitive Information Exposure in Adobe | cvebase