Junglewise Threat Intelligence

CVE-2013-3346: Adobe Reader and Acrobat Memory Corruption Vulnerability

CVE-2013-3346 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-03

Technologies: Adobe Acrobat, Adobe Reader, Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

Adobe Reader and Acrobat contain a memory corruption vulnerability (out-of-bounds write) that allows attackers to execute arbitrary code or cause a denial of service via unspecified vectors. This vulnerability has been observed being exploited in the wild.

Affected products

  • Adobe Reader 9.x before 9.5.5, 10.x before 10.1.7, 11.x before 11.0.03
  • Adobe Acrobat 9.x before 9.5.5, 10.x before 10.1.7, 11.x before 11.0.03

Timeline

  • 2022-03-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
  • 2022-03-03: disclosed

Related threats