CVE-2013-2729 is an integer overflow vulnerability affecting Adobe Reader and Acrobat versions 9.x, 10.x, and 11.x, allowing for arbitrary code execution. This critical vulnerability has a CVSS score of 9.8, indicating a network-exploitable flaw with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, as confirmed by its presence in the KEV catalog, and has garnered significant community attention with numerous discussions. While no Metasploit or Nuclei exploits are listed, an ExploitDB entry for a related heap corruption vulnerability in Adobe Reader X exists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0, < 9.5.5CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 10.0, < 10.1.7CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 11.0, < 11.0.03CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 9.0, < 9.5.5CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* | ||
>= 10.0, < 10.1.7CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.