9.3
CVSSv2

CVE-2013-0640

Published: 14/02/2013 Updated: 19/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Adobe Reader and Acrobat 9.x prior to 9.5.4, 10.x prior to 10.1.6, and 11.x prior to 11.0.02 allow remote malicious users to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as exploited in the wild in February 2013.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

adobe acrobat reader 9.5.2

adobe acrobat reader 9.1.3

adobe acrobat reader 9.4.3

adobe acrobat reader 9.1.1

adobe acrobat reader 9.4.5

adobe acrobat reader 9.3.2

adobe acrobat reader 9.1.2

adobe acrobat reader 9.5.1

adobe acrobat reader 9.3.3

adobe acrobat reader 9.3.1

adobe acrobat reader 9.3

adobe acrobat reader 9.1

adobe acrobat reader 9.4.7

adobe acrobat reader 9.5

adobe acrobat reader 9.0

adobe acrobat reader 9.3.4

adobe acrobat reader 9.5.3

adobe acrobat reader 9.4.1

adobe acrobat reader 9.4.2

adobe acrobat reader 9.2

adobe acrobat reader 9.4.4

adobe acrobat reader 9.4

adobe acrobat reader 9.4.6

adobe acrobat reader 10.1.3

adobe acrobat reader 10.1

adobe acrobat reader 10.1.2

adobe acrobat reader 10.0

adobe acrobat reader 10.0.2

adobe acrobat reader 10.1.1

adobe acrobat reader 10.0.3

adobe acrobat reader 10.1.5

adobe acrobat reader 10.1.4

adobe acrobat reader 10.0.1

adobe acrobat reader 11.0

adobe acrobat reader 11.0.1

adobe acrobat 9.4.5

adobe acrobat 9.4.7

adobe acrobat 9.5.3

adobe acrobat 9.4.4

adobe acrobat 9.4.2

adobe acrobat 9.3

adobe acrobat 9.1

adobe acrobat 9.4.1

adobe acrobat 9.1.3

adobe acrobat 9.2

adobe acrobat 9.1.1

adobe acrobat 9.1.2

adobe acrobat 9.5.2

adobe acrobat 9.5.1

adobe acrobat 9.3.3

adobe acrobat 9.4.3

adobe acrobat 9.3.2

adobe acrobat 9.3.4

adobe acrobat 9.3.1

adobe acrobat 9.0

adobe acrobat 9.4.6

adobe acrobat 9.5

adobe acrobat 9.4

adobe acrobat 10.1.1

adobe acrobat 10.1.3

adobe acrobat 10.1.4

adobe acrobat 10.0

adobe acrobat 10.1

adobe acrobat 10.0.1

adobe acrobat 10.1.5

adobe acrobat 10.0.2

adobe acrobat 10.1.2

adobe acrobat 10.0.3

adobe acrobat 11.0

adobe acrobat 11.0.1

Vendor Advisories

Synopsis Critical: acroread security update Type/Severity Security Advisory: Critical Topic Updated acroread packages that fix two security issues are now availablefor Red Hat Enterprise Linux 5 and 6 SupplementaryThe Red Hat Security Response Team has rated this update as having criticalsecurity impact C ...

Exploits

CVE-2013-0640/1 Somehow, our script got on to the Russian forums :/ @w3bd3vil and @abh1sek Exploit-DB Mirror: githubcom/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/29881targz Adobe Acrobat Reader ASLR/DEP bypass Exploit with SANDBOX BYPASS ================================================================= Supported ...

Recent Articles

Kaspersky Security Bulletin 2013. Corporate threats
Securelist • Vitaly Kamluk Sergey Lozhkin • 05 Dec 2013

Tat’jana Šerbakova PDF Version The number of serious cyber-attacks detected over the last two years has increased so much that new attacks rarely cause much surprise. It’s now commonplace for antivirus companies to issue a report about the discovery of another botnet or highly sophisticated malware campaign that is gathering data. Companies are increasingly falling victim to cyber-attacks. According to a survey conducted by Kaspersky Lab and B2B International, 91% of the organizations polle...

IT Threat Evolution: Q1 2013
Securelist • Denis Maslennikov • 16 May 2013

The first quarter of 2013 turned out to be a busy time in IT security. This report will address the most significant events. At the very beginning of the year, Kaspersky Lab published a significant report with the results of a study on the global cyberespionage operation known as Red October. These attacks targeted various government agencies, diplomatic organizations and companies around the world. Analyzing the files and reconstructing the structure of the attack took several months. However, ...

New Uyghur and Tibetan Themed Attacks Using PDF Exploits
Securelist • Igor Soumenkov Costin Raiu • 14 Mar 2013

On Feb 12th 2013, FireEye announced the discovery of an Adobe Reader 0-day exploit which is used to drop a previously unknown, advanced piece of malware. We called this new malware “ItaDuke” because it reminded us of Duqu and because of the ancient Italian comments in the shellcode copied from Dante Alighieri’s “Divine Comedy”. Previously, we posted about another campaign hitting Governments and other institutions, named Miniduke, which was also using the same “Divine Comedy” PDF e...

The MiniDuke Mystery: PDF 0-day Government Spy Assembler 0x29A Micro Backdoor
Securelist • GReAT • 27 Feb 2013

(or, how many cool words can you fit into one title) On Feb 12th 2013, FireEye announced the discovery of an Adobe Reader 0-day exploit which is used to drop a previously unknown, advanced piece of malware. We called this new malware ?ItaDuke because it reminded us of Duqu and because of the ancient Italian comments in the shellcode copied from Dante Alighieri-s ?Divine Comedy. Since the original announcement, we have observed several new attacks using the same exploit (CVE-2013-0640) which drop...