Security bypass in Adobe Acrobat and Adobe Reader - CVE-2014-0546

 

Security bypass in Adobe Acrobat and Adobe Reader - CVE-2014-0546

Published: January 18, 2017 / Updated: May 25, 2022


Vulnerability identifier: #VU4899
CSH Severity: Critical
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-0546
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to improper input validation when processing .pdf files. A remote attacker can create a specially crafted file, trick the victim into opening it, bypass sandbox restrictions and execute arbitrary code with privileges of the current user.

Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.

Note: the vulnerability was being actively exploited.

Affected software

Adobe Acrobat
Adobe Reader

How to mitigate CVE-2014-0546

Install update from vendor's website.


External References

Related Security Bulletins