← Vulnerability feed

Vulnerability record · CVE-2013-2730 · published 16 May 2013

CVE-2013-2730: Adobe Reader and Acrobat buffer overflow allows code execution

Adobe · Acrobat Reader

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain a buffer overflow (CWE-119) reachable through unspecified vectors. It is distinct from CVE-2013-2733. Successful exploitation permits arbitrary code execution in the context of the affected application.

10.0 CVSS 2.0 High EPSS 79% · top 0.4% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2733.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityThe flaw allows unauthenticated remote code execution with complete impact and has a very high EPSS score with public exploit references, though it is not in CISA KEV and the affected software is long superseded.

What it is

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain a buffer overflow (CWE-119) reachable through unspecified vectors. It is distinct from CVE-2013-2733. Successful exploitation permits arbitrary code execution in the context of the affected application.

Impact

An attacker can execute arbitrary code on the victim's system, potentially leading to full compromise of the user's account and data. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.

Attack surface

The CVSS 2.0 vector (AV:N/AC:L/Au:N) indicates the flaw is reachable over the network with no authentication required. Because the affected products are document readers, exploitation typically requires the victim to open a crafted file, though the description does not specify the exact vector or whether user interaction is mandatory.

Exploitation

CISA KEV does not list this CVE, but EPSS gives a 30-day exploitation probability of 0.78757 (99.57th percentile), and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware group is documented as using it.

What to do

  • Apply the Adobe security bulletin APSB13-15 updates to move Reader and Acrobat to 9.5.5, 10.1.7 or 11.0.03 or later.
  • Apply the referenced Red Hat, openSUSE and Gentoo errata for any bundled or distribution-packaged Reader/Acrobat components.
  • If immediate patching is not possible, restrict opening of untrusted PDF files and disable JavaScript in Reader/Acrobat.
  • Retire or isolate end-of-life Reader and Acrobat 9.x, 10.x and 11.x installations that cannot be brought to a supported release.

Detection

  • Monitor for Reader/Acrobat processes spawning child processes such as cmd.exe, powershell.exe or script interpreters, which is abnormal for a PDF viewer.
  • Hunt for PDF files written to temp or download directories that are immediately opened by Reader or Acrobat, especially from email or web sources.
  • Review endpoint logs for crashes or memory corruption events in AcroRd32.exe or Acrobat.exe that precede suspicious process creation.
  • Check installed Reader and Acrobat versions against the fixed builds (9.5.5, 10.1.7, 11.0.03) to identify unpatched hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-2730 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0546Adobe Reader and Acrobat sandbox bypass allows privileged code executionAdobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reade…KEVEPSS 22%analysed9.8CVE-2013-3346Adobe Reader and Acrobat memory corruption allows code executionAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory.…KEVEPSS 79%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed9.8CVE-2011-2462Adobe Reader and Acrobat U3D memory corruption code executionAn out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The fla…KEVEPSS 89%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2014-0496Adobe Reader and Acrobat use-after-free code executionAdobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary …KEVEPSS 40%analysed8.8CVE-2011-0611Adobe Flash Player type confusion allows remote code executionAdobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Fl…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2013-2730), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.