Adobe Reader and Acrobat known exploited vulnerabilities, ranked
CISA lists 8 Adobe Reader and Acrobat CVEs as exploited in the wild. 0 were added in the last 12 months and 1 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.
Patch these first
- CVE-2009-0927: EPSS 96.6%, added 2022-03-25
- CVE-2011-2462: EPSS 88.9%, added 2022-06-08
- CVE-2010-0188: EPSS 88.2%, used in ransomware, added 2022-03-03
- CVE-2013-0640: EPSS 86.9%, added 2022-03-03
- CVE-2013-3346: EPSS 78.9%, added 2022-03-03
All 8 Adobe Reader and Acrobat CVEs in CISA KEV, by EPSS
| # | CVE | Flaw | EPSS | Ransomware | Added | Federal due |
|---|---|---|---|---|---|---|
| 1 | CVE-2009-0927 | Reader and Acrobat Stack-Based Buffer Overflow | 96.6% | – | 2022-03-25 | 2022-04-15 |
| 2 | CVE-2011-2462 | Reader and Acrobat Universal 3D Memory Corruption | 88.9% | – | 2022-06-08 | 2022-06-22 |
| 3 | CVE-2010-0188 | Reader and Acrobat Arbitrary Code Execution | 88.2% | Yes | 2022-03-03 | 2022-03-24 |
| 4 | CVE-2013-0640 | Reader and Acrobat Memory Corruption | 86.9% | – | 2022-03-03 | 2022-03-24 |
| 5 | CVE-2013-3346 | Reader and Acrobat Memory Corruption | 78.9% | – | 2022-03-03 | 2022-03-24 |
| 6 | CVE-2013-2729 | Reader and Acrobat Arbitrary Integer Overflow | 66.6% | – | 2022-03-28 | 2022-04-18 |
| 7 | CVE-2014-0496 | Reader and Acrobat Use-After-Free | 40.0% | – | 2022-03-03 | 2022-03-24 |
| 8 | CVE-2014-0546 | Reader and Acrobat Sandbox Bypass | 22.3% | – | 2022-05-25 | 2022-06-15 |
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint.
Sources: CISA KEV, FIRST EPSS.
More: all Adobe KEV CVEs · other Adobe products: ColdFusion · Acrobat and Reader · Flash Player · free KEV badge for Adobe · all vendors