Adobe Reader and Acrobat 9.x prior to 9.5.4, 10.x prior to 10.1.6, and 11.x prior to 11.0.02 allow remote malicious users to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as exploited in the wild in February 2013.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
adobe acrobat reader 9.5.2 |
||
adobe acrobat reader 9.1.3 |
||
adobe acrobat reader 9.4.3 |
||
adobe acrobat reader 9.1.1 |
||
adobe acrobat reader 9.4.5 |
||
adobe acrobat reader 9.3.2 |
||
adobe acrobat reader 9.1.2 |
||
adobe acrobat reader 9.5.1 |
||
adobe acrobat reader 9.3.3 |
||
adobe acrobat reader 9.3.1 |
||
adobe acrobat reader 9.3 |
||
adobe acrobat reader 9.1 |
||
adobe acrobat reader 9.4.7 |
||
adobe acrobat reader 9.5 |
||
adobe acrobat reader 9.0 |
||
adobe acrobat reader 9.3.4 |
||
adobe acrobat reader 9.5.3 |
||
adobe acrobat reader 9.4.1 |
||
adobe acrobat reader 9.4.2 |
||
adobe acrobat reader 9.2 |
||
adobe acrobat reader 9.4.4 |
||
adobe acrobat reader 9.4 |
||
adobe acrobat reader 9.4.6 |
||
adobe acrobat reader 10.1.3 |
||
adobe acrobat reader 10.1 |
||
adobe acrobat reader 10.1.2 |
||
adobe acrobat reader 10.0 |
||
adobe acrobat reader 10.0.2 |
||
adobe acrobat reader 10.1.1 |
||
adobe acrobat reader 10.0.3 |
||
adobe acrobat reader 10.1.5 |
||
adobe acrobat reader 10.1.4 |
||
adobe acrobat reader 10.0.1 |
||
adobe acrobat reader 11.0 |
||
adobe acrobat reader 11.0.1 |
||
adobe acrobat 9.4.5 |
||
adobe acrobat 9.4.7 |
||
adobe acrobat 9.5.3 |
||
adobe acrobat 9.4.4 |
||
adobe acrobat 9.4.2 |
||
adobe acrobat 9.3 |
||
adobe acrobat 9.1 |
||
adobe acrobat 9.4.1 |
||
adobe acrobat 9.1.3 |
||
adobe acrobat 9.2 |
||
adobe acrobat 9.1.1 |
||
adobe acrobat 9.1.2 |
||
adobe acrobat 9.5.2 |
||
adobe acrobat 9.5.1 |
||
adobe acrobat 9.3.3 |
||
adobe acrobat 9.4.3 |
||
adobe acrobat 9.3.2 |
||
adobe acrobat 9.3.4 |
||
adobe acrobat 9.3.1 |
||
adobe acrobat 9.0 |
||
adobe acrobat 9.4.6 |
||
adobe acrobat 9.5 |
||
adobe acrobat 9.4 |
||
adobe acrobat 10.1.1 |
||
adobe acrobat 10.1.3 |
||
adobe acrobat 10.1.4 |
||
adobe acrobat 10.0 |
||
adobe acrobat 10.1 |
||
adobe acrobat 10.0.1 |
||
adobe acrobat 10.1.5 |
||
adobe acrobat 10.0.2 |
||
adobe acrobat 10.1.2 |
||
adobe acrobat 10.0.3 |
||
adobe acrobat 11.0 |
||
adobe acrobat 11.0.1 |
Tat’jana Šerbakova PDF Version The number of serious cyber-attacks detected over the last two years has increased so much that new attacks rarely cause much surprise. It’s now commonplace for antivirus companies to issue a report about the discovery of another botnet or highly sophisticated malware campaign that is gathering data. Companies are increasingly falling victim to cyber-attacks. According to a survey conducted by Kaspersky Lab and B2B International, 91% of the organizations polle...
The first quarter of 2013 turned out to be a busy time in IT security. This report will address the most significant events. At the very beginning of the year, Kaspersky Lab published a significant report with the results of a study on the global cyberespionage operation known as Red October. These attacks targeted various government agencies, diplomatic organizations and companies around the world. Analyzing the files and reconstructing the structure of the attack took several months. However, ...
On Feb 12th 2013, FireEye announced the discovery of an Adobe Reader 0-day exploit which is used to drop a previously unknown, advanced piece of malware. We called this new malware “ItaDuke” because it reminded us of Duqu and because of the ancient Italian comments in the shellcode copied from Dante Alighieri’s “Divine Comedy”. Previously, we posted about another campaign hitting Governments and other institutions, named Miniduke, which was also using the same “Divine Comedy” PDF e...
(or, how many cool words can you fit into one title) On Feb 12th 2013, FireEye announced the discovery of an Adobe Reader 0-day exploit which is used to drop a previously unknown, advanced piece of malware. We called this new malware ?ItaDuke because it reminded us of Duqu and because of the ancient Italian comments in the shellcode copied from Dante Alighieri-s ?Divine Comedy. Since the original announcement, we have observed several new attacks using the same exploit (CVE-2013-0640) which drop...