CVE-2013-0641 is a critical buffer overflow vulnerability in Adobe Reader and Acrobat versions 9.x, 10.x, and 11.x, impacting users across Windows, macOS, and Linux. This flaw allows remote attackers to execute arbitrary code by enticing a user to open a specially crafted PDF document. With a CVSS score of 7.8 (High), it presents a significant risk due to its low attack complexity and high potential for confidentiality, integrity, and availability compromise. This vulnerability has been actively exploited in the wild since February 2013, as confirmed by its presence in the KEV catalog, and has garnered substantial community discussion and media coverage despite the lack of public exploit code in Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0, < 9.5.4CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 10.0, < 10.1.6CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 11.0, < 11.0.02CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 10.0, < 10.1.6CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* | ||
>= 11.0, < 11.0.02CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.