Skip to content
COOEY

EXPOSURES › CVE-2014-0496

CVE-2014-0496

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2014-0496 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Adobe Reader and Acrobat suffered a use-after-free vulnerability allowing remote code execution, which was actively exploited in the wild.

Adobe Reader and Acrobat contained a use-after-free vulnerability enabling remote code execution, a flaw that was actively exploited in the wild. This failure is critical for DIB organizations because it represents a high-risk, avoidable exposure where a known vulnerability was not patched before exploitation, directly impacting compliance with NIST 800-171 requirements for vulnerability management and patching. Organizations must ensure their Adobe products are updated to the latest patches and monitor for similar unpatched vulnerabilities in their supply chain.

Shame score — Adobe repeatedly ships critical RCE vulnerabilities in its widely deployed products, and this specific flaw was actively exploited in the wild, demonstrating a pattern of negligence and avoidable exposure that severely damages trust and compliance posture.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized