Vulnerability record · CVE-2014-0496 · published 15 January 2014
CVE-2014-0496: Adobe Reader and Acrobat use-after-free code execution
Adobe · Acrobat
Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary code execution via unspecified vectors. The flaw is remotely reachable and requires a user to open a crafted file, making it a standard client-side document attack. It matters because Reader and Acrobat are widely deployed and the vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with no privileges required, high CVSS (8.8), KEV-listed known exploitation and a high EPSS percentile, tempered only by the required user interaction and the age of the affected versions.
What it is
Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary code execution via unspecified vectors. The flaw is remotely reachable and requires a user to open a crafted file, making it a standard client-side document attack. It matters because Reader and Acrobat are widely deployed and the vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
An attacker who gets a victim to open a malicious PDF can execute arbitrary code in the context of the Reader/Acrobat process, giving full control of confidentiality, integrity and availability on the host.
Attack surface
Reached over the network (AV:N) with no privileges required (PR:N) but user interaction is required (UI:R), consistent with opening a crafted PDF in Reader or Acrobat. No authentication is needed on the target side.
Exploitation
CVE-2014-0496 is in CISA's KEV catalog (added 2022-03-03), indicating known exploitation in the wild, and EPSS shows a 30-day probability of 0.40243 (98.5th percentile). References are vendor advisory, third-party advisory and US government resources; no public exploit code or ransomware association is stated in the record.
What to do
- Apply the Adobe updates referenced in APSB14-01 to move Reader/Acrobat to 10.1.9 or 11.0.06 or later; this is the primary fix.
- If immediate patching is not possible, disable or restrict JavaScript in Reader/Acrobat and enable Protected View/Protected Mode.
- Block or sandbox PDF handling for untrusted sources and enforce attachment filtering at mail and web gateways.
- Retire or isolate end-of-life Reader/Acrobat 10.x and 11.x installations that cannot be updated.
- Verify remediation against CISA KEV required action and track the 2022-03-24 due date for any remaining exposure.
Detection
- Hunt for Reader/Acrobat processes (AcroRd32.exe, Acrobat.exe) spawning child processes such as cmd.exe, powershell.exe or wscript.exe.
- Monitor for unusual file writes or network connections originating from Reader/Acrobat, which normally should not behave like a general-purpose process.
- Search endpoint telemetry for crashes or memory-corruption events in Reader/Acrobat followed by suspicious process creation.
- Review email and web proxy logs for PDFs delivered from untrusted senders or sites to users running unpatched Reader/Acrobat versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2014-0496 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Adobe Reader and Acrobat Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://helpx.adobe.com/security/products/acrobat/apsb14-01.html | Vendor Advisory |
| http://www.securitytracker.com/id/1029604 | Third Party AdvisoryVDB Entry |
| http://helpx.adobe.com/security/products/acrobat/apsb14-01.html | Vendor Advisory |
| http://www.securitytracker.com/id/1029604 | Third Party AdvisoryVDB Entry |
| https://github.com/cisagov/vulnrichment/issues/199 | Issue Tracking |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0496 | US Government Resource |
Track CVE-2014-0496 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-0496), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.