Junglewise Threat Intelligence

CVE-2014-0546: Adobe Reader and Acrobat Sandbox Bypass Vulnerability

CVE-2014-0546 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-05-25

Technologies: Adobe Acrobat, Adobe Reader, Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

Adobe Reader and Acrobat on Windows contain a sandbox bypass vulnerability. This flaw allows remote attackers to escape the sandbox protection mechanism and execute native code with elevated privileges via unspecified vectors.

Affected products

  • Adobe Reader 10.x before 10.1.11, 11.x before 11.0.08
  • Adobe Acrobat 10.x before 10.1.11, 11.x before 11.0.08

Timeline

  • 2014-08-12: disclosed: Initial vendor advisory APSB14-19 published
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-25: other: NVD publication date
  • 2022-06-15: patched: CISA KEV due date for remediation

Related threats