Skip to content
COOEY

FAIL › dossier

Reader and Acrobat

PRODUCT

· dossier confidence 40%

Adobe, a leading software company, faces ongoing security challenges with frequent critical Remote Code Execution (RCE) vulnerabilities in its widely used Acrobat and Reader products, requiring constant vigilance and remediation efforts.

PROFILE
CategorySoftwareWhat they doAdobe Inc. operates as a technology company worldwide, offering products and services that enable individuals, teams, and enterprises to create, publish, and promote content. The company was founded in 1982 and is headquartered in San Jose, California.Founded1982 Websitehttps://stockanalysis.com/stocks/adbe/company/ ↗
SECURITY POSTURE

Adobe has a high-risk track record with repeated critical Remote Code Execution (RCE) vulnerabilities in Acrobat and Reader products. These vulnerabilities have included stack-based buffer overflows, memory corruption, and use-after-free issues.

Notable failures
  • CVE-2010-0188 (RCE)
  • CVE-2009-0927 (RCE)
  • CVE-2013-0640 (RCE)
  • CVE-2014-0496 (RCE)
  • CVE-2013-3346 (RCE)
  • CVE-2011-2462 (RCE)
  • CVE-2014-0546 (Sandbox Bypass)
  • CVE-2013-2729 (RCE)
Patterns: Repeated critical RCE vulnerabilities; Memory corruption vulnerabilities; Sandbox bypass vulnerabilities
FAILURE HISTORY · 8
DATEEVENTSEVSUMMARY
2022-05-25 CVE-2014-0546 high Adobe Reader and Acrobat allowed attackers to bypass sandbox protections and execute privileged native code via CVE-2014-0546.
2022-03-03 CVE-2013-0640 high Adobe Reader and Acrobat contained a memory corruption vulnerability in acroform.dll enabling remote code execution.
2022-03-25 CVE-2009-0927 high Adobe Reader and Acrobat contained a stack-based buffer overflow allowing remote attackers to execute arbitrary code.
2022-06-08 CVE-2011-2462 high A memory corruption vulnerability in Adobe Reader and Acrobat allowed for potential remote code execution and denial-of-service attacks, and is currently being exploited in the wild.
2022-03-28 CVE-2013-2729 high Adobe Reader and Acrobat suffered an arbitrary integer overflow vulnerability allowing remote code execution.
2022-03-03 CVE-2010-0188 critical A critical Adobe Reader/Acrobat vulnerability (CVE-2010-0188) allowed arbitrary code execution and is actively exploited, often linked to ransomware attacks.
2022-03-03 CVE-2014-0496 high Adobe Reader and Acrobat suffered a use-after-free vulnerability allowing remote code execution, which was actively exploited in the wild.
2022-03-03 CVE-2013-3346 high Adobe Reader and Acrobat suffered a memory corruption vulnerability allowing arbitrary code execution, which was actively exploited in the wild.
Open questions: What specific remediation steps are taken to address these recurring vulnerabilities? · What is the extent of Adobe's vulnerability disclosure program? · Are there any known data breaches related to Adobe products?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-19 04:58:13.742253+00:00