Vulnerability record · CVE-2012-4157 · published 15 August 2012
CVE-2012-4157: Adobe Reader and Acrobat memory corruption code execution
Adobe · Acrobat
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X contain a memory corruption flaw (CWE-119) reachable through unspecified vectors. It is one of a large batch of distinct memory corruption issues fixed in the same Adobe bulletin, and successful exploitation can run arbitrary code or crash the application.
Description
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote, unauthenticated code execution with a maximum CVSS 2.0 score and high EPSS, though no confirmed in-the-wild exploitation is recorded.
What it is
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X contain a memory corruption flaw (CWE-119) reachable through unspecified vectors. It is one of a large batch of distinct memory corruption issues fixed in the same Adobe bulletin, and successful exploitation can run arbitrary code or crash the application.
Impact
An attacker can execute arbitrary code in the context of the user running Reader or Acrobat, or cause a denial of service through memory corruption.
Attack surface
The CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates remote, low-complexity exploitation with no authentication required, consistent with a malicious PDF or similar document opened by the victim. The description does not specify the exact vectors, so the precise trigger is unknown.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is high (0.45755, 98.7th percentile), suggesting meaningful exploitation likelihood; reference tags only include Patch and Vendor Advisory, with no public exploit reference.
What to do
- Apply the Adobe fix referenced in APSB12-16, upgrading Reader/Acrobat to 9.5.2 or 10.1.4 or later (or a currently supported release).
- If immediate patching is not possible, restrict or disable JavaScript in Reader/Acrobat and enable Protected View/Enhanced Security.
- Block untrusted PDFs at email and web gateways, and avoid opening documents from unverified sources.
- On Gentoo systems, apply the fix referenced in GLSA 201308-03.
- Retire or isolate end-of-life Reader/Acrobat 9.x and 10.x installations that cannot be updated.
Detection
- Monitor for Reader/Acrobat processes spawning child processes such as cmd.exe, powershell.exe or other shells.
- Alert on crashes of AcroRd32.exe or Acrobat.exe with memory-corruption signatures, especially clustered across hosts.
- Hunt for PDF files written to temp or user directories immediately before process creation events.
- Track endpoint versions of Reader/Acrobat and flag hosts still running 9.x before 9.5.2 or 10.x before 10.1.4.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-4157 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-4157), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.