EXPOSURES › CVE-2014-0496
CVE-2014-0496
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe Reader and Acrobat suffered a use-after-free vulnerability allowing remote code execution, which was actively exploited in the wild.
Adobe Reader and Acrobat contained a use-after-free vulnerability enabling remote code execution, a flaw that was actively exploited in the wild. This failure is critical for DIB organizations because it represents a high-risk, avoidable exposure where a known vulnerability was not patched before exploitation, directly impacting compliance with NIST 800-171 requirements for vulnerability management and patching. Organizations must ensure their Adobe products are updated to the latest patches and monitor for similar unpatched vulnerabilities in their supply chain.
Shame score — Adobe repeatedly ships critical RCE vulnerabilities in its widely deployed products, and this specific flaw was actively exploited in the wild, demonstrating a pattern of negligence and avoidable exposure that severely damages trust and compliance posture.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |