← Vulnerability feed

Vulnerability record · CVE-2011-2462 · published 7 December 2011

CVE-2011-2462: Adobe Reader and Acrobat U3D memory corruption code execution

Adobe · Acrobat

An out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The flaw affects Reader/Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Reader 9.x through 9.4.6 on UNIX. It was exploited in the wild in December 2011, making it a serious client-side risk for anyone opening a malicious PDF.

9.8 CVSS 3.1 Critical CISA KEV since 8 Jun 2022 EPSS 89% · top 0.2% CWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score, v2 10.0
89%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, confirmed in-the-wild exploitation, CISA KEV listing and very high EPSS make this an urgent patch-or-mitigate item.

What it is

An out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The flaw affects Reader/Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Reader 9.x through 9.4.6 on UNIX. It was exploited in the wild in December 2011, making it a serious client-side risk for anyone opening a malicious PDF.

Impact

An attacker can execute arbitrary code in the context of the user running Reader or Acrobat, or crash the application to cause a denial of service. Successful exploitation gives full control of the affected process and potentially the host.

Attack surface

Reached remotely over the network by delivering a crafted PDF or U3D content that the victim opens in Reader or Acrobat. No authentication is required, but exploitation depends on the user opening the malicious file, so user interaction is effectively needed despite the CVSS vector listing UI:N.

Exploitation

Listed in CISA KEV since 2022-06-08 and described as exploited in the wild in December 2011. EPSS is 0.86563 (99.7th percentile), indicating high predicted exploitation activity.

What to do

  • Apply the vendor updates referenced in Adobe advisories APSA11-04 and APSB11-30/APSB12-01, or upgrade to a supported Reader/Acrobat release.
  • If patching is not immediately possible, disable or restrict the U3D/3D content handling in Reader and Acrobat.
  • Block or sandbox untrusted PDF attachments at the email and web gateway.
  • Enable Protected Mode/Protected View and other sandboxing features in Reader and Acrobat.
  • Retire or isolate end-of-life Reader 9.x and 10.x installations on UNIX, Windows and macOS.

Detection

  • Monitor for Reader/Acrobat processes spawning child processes such as cmd.exe, powershell.exe or /bin/sh.
  • Hunt for PDF files containing U3D streams or 3D annotations delivered via email or web downloads.
  • Review endpoint logs for crashes or memory-corruption events in AcroRd32.exe, Acrobat.exe or related Reader binaries.
  • Alert on known exploit indicators and network callbacks from hosts running vulnerable Reader/Acrobat versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2011-2462 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00019.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00020.html Broken Link
http://www.adobe.com/support/security/advisories/apsa11-04.html Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb11-30.html Not Applicable
http://www.adobe.com/support/security/bulletins/apsb12-01.html Not Applicable
http://www.redhat.com/support/errata/RHSA-2012-0011.html Broken Link
http://www.us-cert.gov/cas/techalerts/TA11-350A.html Third Party AdvisoryUS Government Resource
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14562 Broken Link
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00019.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00020.html Broken Link
http://www.adobe.com/support/security/advisories/apsa11-04.html Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb11-30.html Not Applicable
http://www.adobe.com/support/security/bulletins/apsb12-01.html Not Applicable
http://www.redhat.com/support/errata/RHSA-2012-0011.html Broken Link
http://www.us-cert.gov/cas/techalerts/TA11-350A.html Third Party AdvisoryUS Government Resource
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14562 Broken Link
https://github.com/cisagov/vulnrichment/issues/199 Issue Tracking
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-2462 US Government Resource

Track CVE-2011-2462 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0546Adobe Reader and Acrobat sandbox bypass allows privileged code executionAdobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reade…KEVEPSS 22%analysed9.8CVE-2013-3346Adobe Reader and Acrobat memory corruption allows code executionAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory.…KEVEPSS 79%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2014-0496Adobe Reader and Acrobat use-after-free code executionAdobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary …KEVEPSS 40%analysed8.8CVE-2011-0611Adobe Flash Player type confusion allows remote code executionAdobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Fl…KEVEPSS 99%analysed8.8CVE-2009-3953Adobe Reader and Acrobat U3D Out-of-Bounds Write Code ExecutionAdobe Reader and Acrobat fail to properly validate U3D data in PDF documents, causing an out-of-bounds write in the CLODProgressiveMeshDeclaration ha…KEVEPSS 83%analysed

Source: NIST National Vulnerability Database (record CVE-2011-2462), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.