CVE-2012-2049Improper Restriction of Operations within the Bounds of a Memory Buffer in Adobe Acrobat

Severity
10.0CRITICALNVD
EPSS
25.5%
top 3.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 15
Latest updateMay 17

Description

Stack-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

NVDadobe/acrobat_reader29 versions+28
NVDadobe/acrobat30 versions+29

Patches

🔴Vulnerability Details

1
GHSA
GHSA-73r4-gvpf-8pp9: Stack-based buffer overflow in Adobe Reader and Acrobat 92022-05-17

📋Vendor Advisories

1
Red Hat
acroread: multiple code execution flaw (APSB12-16)2012-08-14

💬Community

1
Bugzilla
acroread: multiple code execution flaw (APSB12-16)2012-08-14
CVE-2012-2049 — Adobe Acrobat vulnerability | cvebase