EXPOSURES › CVE-2013-2729
CVE-2013-2729
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe Reader and Acrobat suffered an arbitrary integer overflow vulnerability allowing remote code execution.
This unpatched vulnerability in Adobe Reader and Acrobat allowed attackers to execute arbitrary remote code, directly enabling ransomware and other malware. DIB organizations must ensure all Adobe products are patched to prevent exploitation and maintain compliance with NIST 800-171 requirements for vulnerability management.
Shame score — The vulnerability remained unpatched for years and was actively exploited in the wild, demonstrating severe negligence in Adobe's vulnerability management program.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |