Vulnerability record · CVE-2014-0546 · published 12 August 2014
CVE-2014-0546: Adobe Reader and Acrobat sandbox bypass allows privileged code execution
Adobe · Acrobat
Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reader sandbox and execute native code in a privileged context. The flaw is rated critical and is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via unspecified vectors.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, confirmed inclusion in CISA KEV, and high EPSS percentile indicate active exploitation of a sandbox escape leading to privileged code execution.
What it is
Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reader sandbox and execute native code in a privileged context. The flaw is rated critical and is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
An attacker who escapes the sandbox gains native code execution at the privilege level of the Reader process, enabling full compromise of the affected host.
Attack surface
The CVSS vector indicates network reachability with no privileges and no user interaction required, though the description says only that unspecified vectors are used; the exact delivery mechanism is not detailed in the record.
Exploitation
CVE-2014-0546 is listed in CISA KEV with a 2022-05-25 addition date, and EPSS shows a 30-day probability of 0.2233 (97.5th percentile), indicating observed exploitation activity. No ransomware campaign use is documented.
What to do
- Apply the Adobe security update referenced in APSB14-19 to move Reader/Acrobat to 10.1.11 or 11.0.08 or later.
- If patching is not immediately possible, restrict or disable PDF handling in Reader and use an alternative viewer for untrusted documents.
- Enforce Protected View/Protected Mode and disable JavaScript in Reader where operationally feasible.
- Remove or block outdated Reader and Acrobat installations from endpoints that handle untrusted files.
- Track remediation against the CISA KEV due date of 2022-06-15 for any remaining exposed systems.
Detection
- Monitor for Reader/Acrobat processes spawning unexpected child processes or loading unusual modules, which can indicate sandbox escape.
- Alert on PDF files opening from email attachments, web downloads, or removable media followed by suspicious process creation.
- Review endpoint telemetry for native code execution originating from Reader/Acrobat outside expected plugin paths.
- Audit installed Reader and Acrobat versions to identify hosts still below 10.1.11 or 11.0.08.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2014-0546 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Adobe Reader and Acrobat Sandbox Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 June 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://helpx.adobe.com/security/products/reader/apsb14-19.html | PatchVendor Advisory |
| http://www.securitytracker.com/id/1030711 | Broken LinkThird Party AdvisoryVDB Entry |
| http://helpx.adobe.com/security/products/reader/apsb14-19.html | PatchVendor Advisory |
| http://www.securitytracker.com/id/1030711 | Broken LinkThird Party AdvisoryVDB Entry |
| https://github.com/cisagov/vulnrichment/issues/199 | Issue Tracking |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0546 | US Government Resource |
Track CVE-2014-0546 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-0546), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.