Junglewise Threat Intelligence

CVE-2013-0640: Adobe Reader and Acrobat Memory Corruption Vulnerability

CVE-2013-0640 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2022-03-03

Technologies: Adobe Acrobat, Adobe Reader, Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

A memory corruption vulnerability in Adobe Reader and Acrobat (specifically acroform.dll) allows remote attackers to execute arbitrary code or cause a denial of service via a crafted PDF document. This vulnerability was actively exploited in the wild starting in early 2013.

Affected products

  • Adobe Reader 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02
  • Adobe Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02

Timeline

  • 2013-02: exploited: Exploited in the wild in February 2013.
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats