Skip to content
COOEY

EXPOSURES › CVE-2013-2729

CVE-2013-2729

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-28 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2013-2729 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatchedransomware

Adobe Reader and Acrobat suffered an arbitrary integer overflow vulnerability allowing remote code execution.

This unpatched vulnerability in Adobe Reader and Acrobat allowed attackers to execute arbitrary remote code, directly enabling ransomware and other malware. DIB organizations must ensure all Adobe products are patched to prevent exploitation and maintain compliance with NIST 800-171 requirements for vulnerability management.

Shame score — The vulnerability remained unpatched for years and was actively exploited in the wild, demonstrating severe negligence in Adobe's vulnerability management program.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized