Desktop Software

Memory Corruption

CVE-2014-8446 - Adobe Acrobat/Reader - Memory Corruption

Memory corruption vulnerability that could lead to code execution.

10.0
/ 10
Critical
CVSS v2.0
ADVISORY ID
PS1
PUBLISHED
2022-10-02
CVE IDs
CVE-2014-8446
VENDORS
Adobe
PUBLIC EXPLOIT
None indexed
CWE
PRODUCT
Adobe Reader/Acrobat 10.x-11.0.09
CVSS VECTOR
AV:N/AC:L/Au:N/C:C/I:C/A:C
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Memory corruption vulnerability that could lead to code execution.

A vulnerability, which was classified as critical, was found in Adobe Acrobat and Reader up to 11.0.09. This affects an unknown function. The manipulation with an unknown input leads to memory corruption. This is going to have an impact on confidentiality, integrity, and availability.It is possible to initiate the attack remotely. No form of authentication is needed for exploitation.

Vulnerability details

Vulnerability details

CVE-2014-8446
Critical | 10.0

Memory corruption vulnerability that could lead to code execution. A vulnerability, which was classified as critical, was found in Adobe Acrobat and Reader up to 11.0.09. This affects an unknown function.

Impact:
Complete data disclosure, complete integrity loss, complete denial of service
DISCLOSURE

Disclosure timeline

2014-05-15 Reported to Vendor

2014-05-16 Response received from Vendor

2014-10-22 CVE assigned

2014-12-09 Advisory & Patch released

Credits

Ashfaq Ansari