← Vulnerability feed

Vulnerability record · CVE-2012-4157 · published 15 August 2012

CVE-2012-4157: Adobe Reader and Acrobat memory corruption code execution

Adobe · Acrobat

Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X contain a memory corruption flaw (CWE-119) reachable through unspecified vectors. It is one of a large batch of distinct memory corruption issues fixed in the same Adobe bulletin, and successful exploitation can run arbitrary code or crash the application.

10.0 CVSS 2.0 High EPSS 46% · top 1.2% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote, unauthenticated code execution with a maximum CVSS 2.0 score and high EPSS, though no confirmed in-the-wild exploitation is recorded.

What it is

Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X contain a memory corruption flaw (CWE-119) reachable through unspecified vectors. It is one of a large batch of distinct memory corruption issues fixed in the same Adobe bulletin, and successful exploitation can run arbitrary code or crash the application.

Impact

An attacker can execute arbitrary code in the context of the user running Reader or Acrobat, or cause a denial of service through memory corruption.

Attack surface

The CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates remote, low-complexity exploitation with no authentication required, consistent with a malicious PDF or similar document opened by the victim. The description does not specify the exact vectors, so the precise trigger is unknown.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is high (0.45755, 98.7th percentile), suggesting meaningful exploitation likelihood; reference tags only include Patch and Vendor Advisory, with no public exploit reference.

What to do

  • Apply the Adobe fix referenced in APSB12-16, upgrading Reader/Acrobat to 9.5.2 or 10.1.4 or later (or a currently supported release).
  • If immediate patching is not possible, restrict or disable JavaScript in Reader/Acrobat and enable Protected View/Enhanced Security.
  • Block untrusted PDFs at email and web gateways, and avoid opening documents from unverified sources.
  • On Gentoo systems, apply the fix referenced in GLSA 201308-03.
  • Retire or isolate end-of-life Reader/Acrobat 9.x and 10.x installations that cannot be updated.

Detection

  • Monitor for Reader/Acrobat processes spawning child processes such as cmd.exe, powershell.exe or other shells.
  • Alert on crashes of AcroRd32.exe or Acrobat.exe with memory-corruption signatures, especially clustered across hosts.
  • Hunt for PDF files written to temp or user directories immediately before process creation events.
  • Track endpoint versions of Reader/Acrobat and flag hosts still running 9.x before 9.5.2 or 10.x before 10.1.4.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-4157 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0546Adobe Reader and Acrobat sandbox bypass allows privileged code executionAdobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reade…KEVEPSS 22%analysed9.8CVE-2013-3346Adobe Reader and Acrobat memory corruption allows code executionAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory.…KEVEPSS 79%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed9.8CVE-2011-2462Adobe Reader and Acrobat U3D memory corruption code executionAn out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The fla…KEVEPSS 89%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2014-0496Adobe Reader and Acrobat use-after-free code executionAdobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary …KEVEPSS 40%analysed8.8CVE-2011-0611Adobe Flash Player type confusion allows remote code executionAdobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Fl…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2012-4157), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.