Junglewise Threat Intelligence

CVE-2014-0496: Adobe Reader and Acrobat Use-After-Free Vulnerability

CVE-2014-0496 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-03

Technologies: Adobe Acrobat, Adobe Reader, Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

A use-after-free vulnerability exists in Adobe Reader and Acrobat on Windows and Mac OS X. The flaw allows remote attackers to execute arbitrary code via unspecified vectors.

Affected products

  • Adobe Reader 10.x before 10.1.9, 11.x before 11.0.06
  • Adobe Acrobat 10.x before 10.1.9, 11.x before 11.0.06

Timeline

  • 2014-01-15: disclosed: NVD Published Date
  • 2022-03-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-03: advisory: Published date listed in advisory summary

Related threats