CVE-2011-2462
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 87% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-787
מוצרים מושפעים
adobe: acrobat; adobe: acrobat reader; apple: mac os x; microsoft: windows; opengroup: unix
קישורים
- http://www.adobe.com/support/security/advisories/apsa11-04.html Vendor Advisory
- http://www.adobe.com/support/security/advisories/apsa11-04.html Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00019.html Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00020.html Broken Link
- http://www.adobe.com/support/security/bulletins/apsb11-30.html Not Applicable
- http://www.adobe.com/support/security/bulletins/apsb12-01.html Not Applicable
- http://www.redhat.com/support/errata/RHSA-2012-0011.html Broken Link
- http://www.us-cert.gov/cas/techalerts/TA11-350A.html Third Party AdvisoryUS Government Resource
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval… Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00019.html Broken Link