Skip to content
COOEY

EXPOSURES › CVE-2011-2462

CVE-2011-2462

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-06-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2011-2462 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

A memory corruption vulnerability in Adobe Reader and Acrobat allowed for potential remote code execution and denial-of-service attacks, and is currently being exploited in the wild.

A memory corruption flaw in Adobe Reader and Acrobat (CVE-2011-2462) enables remote code execution, posing a significant risk to DIB organizations heavily reliant on these products. This vulnerability is actively exploited, potentially leading to system compromise and compliance failures under CMMC/NIST 800-171. Immediate patching and vulnerability scanning are crucial.

Shame score — Adobe's history of repeated, critical RCE vulnerabilities in widely-used products demonstrates a pattern of negligence and insufficient security practices.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS).

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized