Executive brief
Adobe Acrobat and Reader contain an out-of-bounds write vulnerability in the Universal 3D (U3D) implementation. Remote attackers can execute arbitrary code via malformed U3D data in a PDF document, specifically related to the CLODProgressiveMeshDeclaration array boundary issue.
Affected products
- Adobe Acrobat 9.x before 9.3, 8.x before 8.2, 7.x before 7.1.4
- Adobe Reader 9.x before 9.3, 8.x before 8.2, 7.x before 7.1.4
Timeline
- 2010-01-12: advisory: Adobe security bulletin APSB10-02 published
- 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-06-08: disclosed