CVE-2013-0640 is a critical memory corruption vulnerability affecting Adobe Reader and Acrobat versions 9.x, 10.x, and 11.x across Windows, macOS, and Linux. This vulnerability allows remote attackers to execute arbitrary code or cause a denial of service through a crafted PDF document. With a CVSS score of 7.8 (High), it has a low attack complexity and requires user interaction (opening a malicious PDF), but can lead to complete compromise of confidentiality, integrity, and availability. This CVE is listed in the KEV catalog, indicating active exploitation in the wild, notably in February 2013, and has garnered significant community discussion and media coverage, including reports of its use in targeted attacks. While no Metasploit or Nuclei modules are available, an ExploitDB entry details an ASLR, DEP, and sandbox bypass.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0, < 9.5.4CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 10.0, < 10.1.6CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 11.0, < 11.0.02CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 10.0, < 10.1.6CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* | ||
>= 11.0, < 11.0.02CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.