CVE-2013-0640
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
Adobe Reader and Acrobat have a memory corruption flaw that allows attackers to run malicious code or crash the program when you open a specially crafted PDF file. This vulnerability was actively exploited by criminals in early 2013.
Out-of-bounds write vulnerability in Adobe Reader/Acrobat 9.x, 10.x, and 11.x enables remote code execution or denial of service through a malicious PDF document. The attack requires user interaction (opening the PDF) and results in arbitrary code execution with user privileges.
The full analysis of this CVE is available in Portuguese →