CVE-2014-0496 is a critical use-after-free vulnerability affecting Adobe Reader and Acrobat versions 10.x before 10.1.9 and 11.x before 11.0.06 on both Windows and Mac OS X. This flaw allows remote attackers to execute arbitrary code through unspecified vectors, posing a significant risk to affected systems. With a CVSS score of 8.8 (High), it indicates a readily exploitable vulnerability requiring no authentication, though user interaction is likely involved. This CVE is listed in CISA's KEV catalog, confirming active exploitation in the wild, and has garnered substantial community discussion, despite a lack of public exploit intelligence on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0, < 10.1.9CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 11.0, < 11.0.6CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.