EXPOSURES › CVE-2010-2883
CVE-2010-2883
HIGH ⌖ ON CISA KEV · EXPLOITEDA buffer overflow in Adobe Acrobat and Reader allowed attackers to execute code remotely, actively exploited in the wild and impacting DIB organizations using these products.
A stack-based buffer overflow vulnerability (CVE-2010-2883) in Adobe Acrobat and Reader enabled remote code execution and denial-of-service. DIB organizations relying on these products face significant risk of compromise, potentially impacting CMMC compliance and requiring immediate patching and mitigation. Ensure Acrobat and Reader are updated promptly and consider alternative solutions where feasible.
Shame score — Adobe's repeated history of critical RCE vulnerabilities in widely-used products demonstrates a pattern of negligence and insufficient security practices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |