⚠ Actively exploited
Added to CISA KEV on 2022-03-03. Federal agencies required to patch by 2022-03-24. Required action: Apply updates per vendor instructions..

CVE-2013-3346Improper Restriction of Operations within the Bounds of a Memory Buffer in Adobe Acrobat

Severity
9.8CRITICALNVD
EPSS
89.9%
top 0.42%
CISA KEV
KEV
Added 2022-03-03
Due 2022-03-24
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedAug 30
KEV addedMar 3
KEV dueMar 24
Latest updateSep 22
CISA Required Action: Apply updates per vendor instructions.

Description

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-201

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDadobe/acrobat_reader9.09.5.5+2
NVDadobe/acrobat9.09.5.5+2

🔴Vulnerability Details

2
GHSA
GHSA-mhw3-773g-72wx: Adobe Reader and Acrobat 92022-05-17
VulnCheck
Adobe Reader and Acrobat Memory Corruption Vulnerability2013

💥Exploits & PoCs

3
Exploit-DB
Adobe Reader ToolButton - Use-After-Free (Metasploit)2013-12-17
Metasploit
Adobe Reader ToolButton Use After Free
Metasploit
Adobe Reader ToolButton Use After Free

📋Vendor Advisories

2
CISA
Adobe Reader and Acrobat Memory Corruption Vulnerability2022-03-03
Red Hat
acroread: multiple code execution flaws (APSB13-15)2013-05-14

🕵️Threat Intelligence

5
Trendmicro
Examining the Activities of the Turla APT Group2023-09-22
Talos
Microsoft Update Tuesday: January 2014, fix for the XP/2003 0-day vulnerability2014-01-14
Talos
Microsoft Update Tuesday: January 2014, fix for the XP/2003 0-day vulnerability2014-01-14
Talos
Microsoft Update Tuesday: December 2013, some 0-day fixes2013-12-10
Talos
Microsoft Update Tuesday: December 2013, some 0-day fixes2013-12-10

💬Community

1
Bugzilla
acroread: multiple code execution flaws (APSB13-15)2013-05-14
CVE-2013-3346 — Adobe Acrobat vulnerability | cvebase