← Vulnerability feed

Vulnerability record · CVE-2014-0546 · published 12 August 2014

CVE-2014-0546: Adobe Reader and Acrobat sandbox bypass allows privileged code execution

Adobe · Acrobat

Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reader sandbox and execute native code in a privileged context. The flaw is rated critical and is listed in CISA's Known Exploited Vulnerabilities catalog.

9.8 CVSS 3.1 Critical CISA KEV since 25 May 2022 EPSS 22% · top 2.4%
9.8CVSS 3.1 base score, v2 10.0
22%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via unspecified vectors.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityCVSS 9.8, confirmed inclusion in CISA KEV, and high EPSS percentile indicate active exploitation of a sandbox escape leading to privileged code execution.

What it is

Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reader sandbox and execute native code in a privileged context. The flaw is rated critical and is listed in CISA's Known Exploited Vulnerabilities catalog.

Impact

An attacker who escapes the sandbox gains native code execution at the privilege level of the Reader process, enabling full compromise of the affected host.

Attack surface

The CVSS vector indicates network reachability with no privileges and no user interaction required, though the description says only that unspecified vectors are used; the exact delivery mechanism is not detailed in the record.

Exploitation

CVE-2014-0546 is listed in CISA KEV with a 2022-05-25 addition date, and EPSS shows a 30-day probability of 0.2233 (97.5th percentile), indicating observed exploitation activity. No ransomware campaign use is documented.

What to do

  • Apply the Adobe security update referenced in APSB14-19 to move Reader/Acrobat to 10.1.11 or 11.0.08 or later.
  • If patching is not immediately possible, restrict or disable PDF handling in Reader and use an alternative viewer for untrusted documents.
  • Enforce Protected View/Protected Mode and disable JavaScript in Reader where operationally feasible.
  • Remove or block outdated Reader and Acrobat installations from endpoints that handle untrusted files.
  • Track remediation against the CISA KEV due date of 2022-06-15 for any remaining exposed systems.

Detection

  • Monitor for Reader/Acrobat processes spawning unexpected child processes or loading unusual modules, which can indicate sandbox escape.
  • Alert on PDF files opening from email attachments, web downloads, or removable media followed by suspicious process creation.
  • Review endpoint telemetry for native code execution originating from Reader/Acrobat outside expected plugin paths.
  • Audit installed Reader and Acrobat versions to identify hosts still below 10.1.11 or 11.0.08.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2014-0546 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Adobe Reader and Acrobat Sandbox Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 June 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-0546 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2013-3346Adobe Reader and Acrobat memory corruption allows code executionAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory.…KEVEPSS 79%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed9.8CVE-2011-2462Adobe Reader and Acrobat U3D memory corruption code executionAn out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The fla…KEVEPSS 89%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2014-0496Adobe Reader and Acrobat use-after-free code executionAdobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary …KEVEPSS 40%analysed8.8CVE-2011-0611Adobe Flash Player type confusion allows remote code executionAdobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Fl…KEVEPSS 99%analysed8.8CVE-2009-3953Adobe Reader and Acrobat U3D Out-of-Bounds Write Code ExecutionAdobe Reader and Acrobat fail to properly validate U3D data in PDF documents, causing an out-of-bounds write in the CLODProgressiveMeshDeclaration ha…KEVEPSS 83%analysed

Source: NIST National Vulnerability Database (record CVE-2014-0546), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.