CVE-2013-0640highunder attackCWE-787

CVE-2013-0640

Published · Updated

93Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 7.8epss 87%
from disclosure to weapon287 days
Published on NVDFeb 14
1st PoC+287d
CISA KEV+3304d
exploitation probability
87%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
4 products (8 components)
Red Hat Enterprise Linux Desktop Supplementary (v. 6) · Red Hat Enterprise Linux Server Supplementary (v. 5) · Red Hat Enterprise Linux Server Supplementary (v. 6) · Red Hat Enterprise Linux Workstation Supplementary (v. 6)
Action required by CISAfederal deadline: 2022-03-24

Apply updates per vendor instructions.

In short

Adobe Reader and Acrobat have a memory corruption flaw that allows attackers to run malicious code or crash the program when you open a specially crafted PDF file. This vulnerability was actively exploited by criminals in early 2013.

Technical detail

Out-of-bounds write vulnerability in Adobe Reader/Acrobat 9.x, 10.x, and 11.x enables remote code execution or denial of service through a malicious PDF document. The attack requires user interaction (opening the PDF) and results in arbitrary code execution with user privileges.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as exploited in the wild in February 2013.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.