Vulnerability record · CVE-2011-2462 · published 7 December 2011
CVE-2011-2462: Adobe Reader and Acrobat U3D memory corruption code execution
Adobe · Acrobat
An out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The flaw affects Reader/Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Reader 9.x through 9.4.6 on UNIX. It was exploited in the wild in December 2011, making it a serious client-side risk for anyone opening a malicious PDF.
Description
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, confirmed in-the-wild exploitation, CISA KEV listing and very high EPSS make this an urgent patch-or-mitigate item.
What it is
An out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The flaw affects Reader/Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Reader 9.x through 9.4.6 on UNIX. It was exploited in the wild in December 2011, making it a serious client-side risk for anyone opening a malicious PDF.
Impact
An attacker can execute arbitrary code in the context of the user running Reader or Acrobat, or crash the application to cause a denial of service. Successful exploitation gives full control of the affected process and potentially the host.
Attack surface
Reached remotely over the network by delivering a crafted PDF or U3D content that the victim opens in Reader or Acrobat. No authentication is required, but exploitation depends on the user opening the malicious file, so user interaction is effectively needed despite the CVSS vector listing UI:N.
Exploitation
Listed in CISA KEV since 2022-06-08 and described as exploited in the wild in December 2011. EPSS is 0.86563 (99.7th percentile), indicating high predicted exploitation activity.
What to do
- Apply the vendor updates referenced in Adobe advisories APSA11-04 and APSB11-30/APSB12-01, or upgrade to a supported Reader/Acrobat release.
- If patching is not immediately possible, disable or restrict the U3D/3D content handling in Reader and Acrobat.
- Block or sandbox untrusted PDF attachments at the email and web gateway.
- Enable Protected Mode/Protected View and other sandboxing features in Reader and Acrobat.
- Retire or isolate end-of-life Reader 9.x and 10.x installations on UNIX, Windows and macOS.
Detection
- Monitor for Reader/Acrobat processes spawning child processes such as cmd.exe, powershell.exe or /bin/sh.
- Hunt for PDF files containing U3D streams or 3D annotations delivered via email or web downloads.
- Review endpoint logs for crashes or memory-corruption events in AcroRd32.exe, Acrobat.exe or related Reader binaries.
- Alert on known exploit indicators and network callbacks from hosts running vulnerable Reader/Acrobat versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2011-2462 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-2462 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-2462), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.