CVE-2013-3346highunder attackCWE-787

CVE-2013-3346

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 8.8epss 79%
from disclosure to weapon109 days
Published on NVDAug 30
1st PoC+109d
metasploitAug 8
CISA KEV+3107d
exploitation probability
79%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
4 products (8 components)
Red Hat Enterprise Linux Desktop Supplementary (v. 6) · Red Hat Enterprise Linux Server Supplementary (v. 5) · Red Hat Enterprise Linux Server Supplementary (v. 6) · Red Hat Enterprise Linux Workstation Supplementary (v. 6)
Action required by CISAfederal deadline: 2022-03-24

Apply updates per vendor instructions.

In short

Adobe Reader and Acrobat versions 9, 10, and 11 contain a memory corruption flaw that allows attackers to run malicious code or crash the application by opening a specially crafted document. This is a critical vulnerability because these are widely used applications for viewing PDF files.

Technical detail

Out-of-bounds write vulnerability (CWE-787) in Adobe Reader/Acrobat 9.x, 10.x, and 11.x triggered via unspecified vectors in PDF processing. Exploitation requires user interaction (opening a malicious PDF), but results in arbitrary code execution with application privileges or denial of service through memory corruption.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.