EXPOSURES › CVE-2013-0641
CVE-2013-0641
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe Reader's unpatched buffer overflow vulnerability allowed remote code execution and was actively exploited in the wild.
An unpatched buffer overflow in Adobe Reader enabled remote code execution, a flaw that remained unpatched long enough to be added to CISA's KEV catalog. DIB organizations must enforce strict patch management for Adobe products and monitor KEV entries to prevent similar exploits. Failure to patch such vulnerabilities exposes systems to arbitrary code execution and potential data compromise.
Shame score — The vulnerability was unpatched for years, was actively exploited in the wild, and was linked to ransomware campaigns, demonstrating severe negligence in patch management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |