Skip to content
COOEY

EXPOSURES › CVE-2013-0641

CVE-2013-0641

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2013-0641 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatchedransomware

Adobe Reader's unpatched buffer overflow vulnerability allowed remote code execution and was actively exploited in the wild.

An unpatched buffer overflow in Adobe Reader enabled remote code execution, a flaw that remained unpatched long enough to be added to CISA's KEV catalog. DIB organizations must enforce strict patch management for Adobe products and monitor KEV entries to prevent similar exploits. Failure to patch such vulnerabilities exposes systems to arbitrary code execution and potential data compromise.

Shame score — The vulnerability was unpatched for years, was actively exploited in the wild, and was linked to ransomware campaigns, demonstrating severe negligence in patch management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized