Skip to content
COOEY

EXPOSURES › CVE-2013-0640

CVE-2013-0640

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2013-0640 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Adobe Reader and Acrobat contained a memory corruption vulnerability in acroform.dll enabling remote code execution.

An unpatched memory corruption flaw in Adobe Reader's acroform.dll allowed attackers to execute arbitrary code remotely. DIB organizations must ensure Acrobat and Reader are patched immediately, as Adobe has a history of critical RCE vulnerabilities that are frequently exploited in the wild.

Shame score — Adobe repeatedly ships critical RCE vulnerabilities in its widely deployed products, demonstrating a pattern of avoidable negligence that leaves DIB systems exposed to active exploitation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized