Vulnerability record · CVE-2013-2730 · published 16 May 2013
CVE-2013-2730: Adobe Reader and Acrobat buffer overflow allows code execution
Adobe · Acrobat Reader
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain a buffer overflow (CWE-119) reachable through unspecified vectors. It is distinct from CVE-2013-2733. Successful exploitation permits arbitrary code execution in the context of the affected application.
Description
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2733.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows unauthenticated remote code execution with complete impact and has a very high EPSS score with public exploit references, though it is not in CISA KEV and the affected software is long superseded.
What it is
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain a buffer overflow (CWE-119) reachable through unspecified vectors. It is distinct from CVE-2013-2733. Successful exploitation permits arbitrary code execution in the context of the affected application.
Impact
An attacker can execute arbitrary code on the victim's system, potentially leading to full compromise of the user's account and data. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.
Attack surface
The CVSS 2.0 vector (AV:N/AC:L/Au:N) indicates the flaw is reachable over the network with no authentication required. Because the affected products are document readers, exploitation typically requires the victim to open a crafted file, though the description does not specify the exact vector or whether user interaction is mandatory.
Exploitation
CISA KEV does not list this CVE, but EPSS gives a 30-day exploitation probability of 0.78757 (99.57th percentile), and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware group is documented as using it.
What to do
- Apply the Adobe security bulletin APSB13-15 updates to move Reader and Acrobat to 9.5.5, 10.1.7 or 11.0.03 or later.
- Apply the referenced Red Hat, openSUSE and Gentoo errata for any bundled or distribution-packaged Reader/Acrobat components.
- If immediate patching is not possible, restrict opening of untrusted PDF files and disable JavaScript in Reader/Acrobat.
- Retire or isolate end-of-life Reader and Acrobat 9.x, 10.x and 11.x installations that cannot be brought to a supported release.
Detection
- Monitor for Reader/Acrobat processes spawning child processes such as cmd.exe, powershell.exe or script interpreters, which is abnormal for a PDF viewer.
- Hunt for PDF files written to temp or download directories that are immediately opened by Reader or Acrobat, especially from email or web sources.
- Review endpoint logs for crashes or memory corruption events in AcroRd32.exe or Acrobat.exe that precede suspicious process creation.
- Check installed Reader and Acrobat versions against the fixed builds (9.5.5, 10.1.7, 11.0.03) to identify unpatched hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-2730 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-2730), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.