CVE-2012-1525Improper Restriction of Operations within the Bounds of a Memory Buffer in Adobe Acrobat

Severity
10.0CRITICALNVD
EPSS
36.1%
top 2.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 15
Latest updateMay 17

Description

Heap-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

NVDadobe/acrobat_reader29 versions+28
NVDadobe/acrobat30 versions+29

Patches

🔴Vulnerability Details

1
GHSA
GHSA-4h8m-9p94-p7wr: Heap-based buffer overflow in Adobe Reader and Acrobat 92022-05-17

📋Vendor Advisories

1
Red Hat
acroread: multiple code execution flaw (APSB12-16)2012-08-14

💬Community

1
Bugzilla
acroread: multiple code execution flaw (APSB12-16)2012-08-14
CVE-2012-1525 — Adobe Acrobat vulnerability | cvebase