Junglewise Threat Intelligence

CVE-2011-2462: Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability

CVE-2011-2462 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-06-08

Technologies: Adobe Acrobat, Adobe Reader, Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

A memory corruption vulnerability exists in the Universal 3D (U3D) component of Adobe Reader and Acrobat. Remote attackers can exploit this flaw via unknown vectors to execute arbitrary code or cause a denial of service.

Affected products

  • Adobe Reader 10.1.1 and earlier, 9.x through 9.4.6
  • Adobe Acrobat 10.1.1 and earlier

Timeline

  • 2011-12: exploited: Exploited in the wild in December 2011.
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats