← Vulnerability feed

Vulnerability record · CVE-2014-0496 · published 15 January 2014

CVE-2014-0496: Adobe Reader and Acrobat use-after-free code execution

Adobe · Acrobat

Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary code execution via unspecified vectors. The flaw is remotely reachable and requires a user to open a crafted file, making it a standard client-side document attack. It matters because Reader and Acrobat are widely deployed and the vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.

8.8 CVSS 3.1 High CISA KEV since 3 Mar 2022 EPSS 40% · top 1.4% CWE-416 · Use after free
8.8CVSS 3.1 base score, v2 10.0
40%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityRemote code execution with no privileges required, high CVSS (8.8), KEV-listed known exploitation and a high EPSS percentile, tempered only by the required user interaction and the age of the affected versions.

What it is

Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary code execution via unspecified vectors. The flaw is remotely reachable and requires a user to open a crafted file, making it a standard client-side document attack. It matters because Reader and Acrobat are widely deployed and the vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.

Impact

An attacker who gets a victim to open a malicious PDF can execute arbitrary code in the context of the Reader/Acrobat process, giving full control of confidentiality, integrity and availability on the host.

Attack surface

Reached over the network (AV:N) with no privileges required (PR:N) but user interaction is required (UI:R), consistent with opening a crafted PDF in Reader or Acrobat. No authentication is needed on the target side.

Exploitation

CVE-2014-0496 is in CISA's KEV catalog (added 2022-03-03), indicating known exploitation in the wild, and EPSS shows a 30-day probability of 0.40243 (98.5th percentile). References are vendor advisory, third-party advisory and US government resources; no public exploit code or ransomware association is stated in the record.

What to do

  • Apply the Adobe updates referenced in APSB14-01 to move Reader/Acrobat to 10.1.9 or 11.0.06 or later; this is the primary fix.
  • If immediate patching is not possible, disable or restrict JavaScript in Reader/Acrobat and enable Protected View/Protected Mode.
  • Block or sandbox PDF handling for untrusted sources and enforce attachment filtering at mail and web gateways.
  • Retire or isolate end-of-life Reader/Acrobat 10.x and 11.x installations that cannot be updated.
  • Verify remediation against CISA KEV required action and track the 2022-03-24 due date for any remaining exposure.

Detection

  • Hunt for Reader/Acrobat processes (AcroRd32.exe, Acrobat.exe) spawning child processes such as cmd.exe, powershell.exe or wscript.exe.
  • Monitor for unusual file writes or network connections originating from Reader/Acrobat, which normally should not behave like a general-purpose process.
  • Search endpoint telemetry for crashes or memory-corruption events in Reader/Acrobat followed by suspicious process creation.
  • Review email and web proxy logs for PDFs delivered from untrusted senders or sites to users running unpatched Reader/Acrobat versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2014-0496 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Adobe Reader and Acrobat Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-0496 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0546Adobe Reader and Acrobat sandbox bypass allows privileged code executionAdobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reade…KEVEPSS 22%analysed9.8CVE-2013-3346Adobe Reader and Acrobat memory corruption allows code executionAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory.…KEVEPSS 79%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed9.8CVE-2011-2462Adobe Reader and Acrobat U3D memory corruption code executionAn out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The fla…KEVEPSS 89%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2011-0611Adobe Flash Player type confusion allows remote code executionAdobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Fl…KEVEPSS 99%analysed8.8CVE-2009-3953Adobe Reader and Acrobat U3D Out-of-Bounds Write Code ExecutionAdobe Reader and Acrobat fail to properly validate U3D data in PDF documents, causing an out-of-bounds write in the CLODProgressiveMeshDeclaration ha…KEVEPSS 83%analysed

Source: NIST National Vulnerability Database (record CVE-2014-0496), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.