Junglewise Threat Intelligence

CVE-2013-2729: Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability

CVE-2013-2729 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-28

Technologies: Adobe Acrobat, Adobe Reader, Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

An integer overflow vulnerability in Adobe Reader and Acrobat 9.x, 10.x, and 11.x allows remote attackers to execute arbitrary code via unspecified vectors. This vulnerability has been observed being exploited in the wild.

Affected products

  • Adobe Acrobat 9.x before 9.5.5, 10.x before 10.1.7, 11.x before 11.0.03
  • Adobe Reader 9.x before 9.5.5, 10.x before 10.1.7, 11.x before 11.0.03

Timeline

  • 2013-05-14: patched: Adobe released APSB13-15 to address the vulnerability.
  • 2022-03-28: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.

Related threats