← Vulnerability feed

Vulnerability record · CVE-2013-3346 · published 30 August 2013

CVE-2013-3346: Adobe Reader and Acrobat memory corruption allows code execution

Adobe · Acrobat

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory. Successful exploitation lets an attacker execute arbitrary code or crash the application. The flaw is remotely reachable and requires no privileges or user interaction per the CVSS vector.

9.8 CVSS 3.1 Critical CISA KEV since 3 Mar 2022 EPSS 79% · top 0.4% CWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score, v2 10.0
79%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, active exploitation per CISA KEV, and very high EPSS probability make this an urgent patching priority.

What it is

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory. Successful exploitation lets an attacker execute arbitrary code or crash the application. The flaw is remotely reachable and requires no privileges or user interaction per the CVSS vector.

Impact

An attacker can execute arbitrary code in the context of the affected Reader or Acrobat process, or cause a denial of service. This can lead to full compromise of the user's system.

Attack surface

The vulnerability is network-reachable (AV:N) with no authentication (PR:N) and no user interaction (UI:N) per the CVSS vector, though the description does not specify the exact delivery vector. It is reached through the processing of malicious content by Adobe Reader or Acrobat.

Exploitation

CVE-2013-3346 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03) and has an EPSS 30-day probability of 0.78581 (99.564th percentile), indicating active exploitation and high likelihood. No ransomware campaign use is documented.

What to do

  • Apply the vendor update per Adobe security bulletin APSB13-15 to move to Reader/Acrobat 9.5.5, 10.1.7, or 11.0.03 or later.
  • If patching is not immediately possible, disable or restrict the opening of untrusted PDF files and limit JavaScript in Reader/Acrobat.
  • Enforce application allowlisting and least privilege so Reader/Acrobat do not run with administrative rights.
  • Monitor CISA KEV guidance and ensure the due date (2022-03-24) remediation is completed.

Detection

  • Hunt for unusual child processes spawned by AcroRd32.exe or Acrobat.exe, such as cmd.exe, powershell.exe, or scripting hosts.
  • Monitor for crashes or memory corruption events in Adobe Reader/Acrobat via Windows Error Reporting or endpoint telemetry.
  • Review proxy and email logs for PDF files delivered from untrusted sources, especially those matching known exploit patterns.
  • Use EDR to detect exploitation primitives like heap spraying or return-oriented programming behavior in Reader/Acrobat processes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2013-3346 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Adobe Reader and Acrobat Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-3346 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0546Adobe Reader and Acrobat sandbox bypass allows privileged code executionAdobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reade…KEVEPSS 22%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed9.8CVE-2011-2462Adobe Reader and Acrobat U3D memory corruption code executionAn out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The fla…KEVEPSS 89%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2014-0496Adobe Reader and Acrobat use-after-free code executionAdobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary …KEVEPSS 40%analysed8.8CVE-2011-0611Adobe Flash Player type confusion allows remote code executionAdobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Fl…KEVEPSS 99%analysed8.8CVE-2009-3953Adobe Reader and Acrobat U3D Out-of-Bounds Write Code ExecutionAdobe Reader and Acrobat fail to properly validate U3D data in PDF documents, causing an out-of-bounds write in the CLODProgressiveMeshDeclaration ha…KEVEPSS 83%analysed

Source: NIST National Vulnerability Database (record CVE-2013-3346), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.