Adobe Acrobat and Reader U3D Memory Corruption Vulnerability
10 Apr. 2011
Summary
This allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.
Vulnerable Systems:
* Adobe Reader 10.1.1
* Adobe Reader 9.4.6
* Adobe Reader 9.3.4
* Adobe Reader 9.3.4
* Adobe Reader 9.3.3
* Adobe Reader 9.3.2
* Adobe Reader 9.3.1
* Adobe Reader 9.1.3
* Adobe Reader 9.1.2
* Adobe Reader 9.1.1
* Adobe Reader 9.4.5
* Adobe Reader 9.4.4
* Adobe Reader 9.4.3
* Adobe Reader 9.4.2
* Adobe Reader 9.4.1
* Adobe Reader 9.4
* Adobe Reader 9.3
* Adobe Reader 9.2
* Adobe Reader 9.1
* Adobe Reader 9
* Adobe Reader 10.1
* Adobe Reader 10.0.3
* Adobe Reader 10.0.2
* Adobe Reader 10.0.1
* Adobe Reader 10.0
* Adobe Acrobat Standard 10.1.1
* Adobe Acrobat Standard 9.4.6
* Adobe Acrobat Standard 9.3.4
* Adobe Acrobat Standard 9.3.4
* Adobe Acrobat Standard 9.3.3
* Adobe Acrobat Standard 9.3.2
* Adobe Acrobat Standard 9.3.1
* Adobe Acrobat Standard 9.1.3
* Adobe Acrobat Standard 9.1.2
* Adobe Acrobat Standard 9.4.5
* Adobe Acrobat Standard 9.4.4
* Adobe Acrobat Standard 9.4.3
* Adobe Acrobat Standard 9.4.2
* Adobe Acrobat Standard 9.4.1
* Adobe Acrobat Standard 9.4
* Adobe Acrobat Standard 9.3
* Adobe Acrobat Standard 9.2
* Adobe Acrobat Standard 9.1
* Adobe Acrobat Standard 10.1
* Adobe Acrobat Standard 10.0.3
* Adobe Acrobat Standard 10.0.2
* Adobe Acrobat Standard 10.0.1
* Adobe Acrobat Professional 10.1.1
* Adobe Acrobat Professional 9.4.6
* Adobe Acrobat Professional 9.3.4
* Adobe Acrobat Professional 9.3.3
* Adobe Acrobat Professional 9.3.2
* Adobe Acrobat Professional 9.3.1
* Adobe Acrobat Professional 9.1.3
* Adobe Acrobat Professional 9.1.2
* Adobe Acrobat Professional 9.4.5
* Adobe Acrobat Professional 9.4.4
* Adobe Acrobat Professional 9.4.3
* Adobe Acrobat Professional 9.4.2
* Adobe Acrobat Professional 9.4.1
* Adobe Acrobat Professional 9.4
* Adobe Acrobat Professional 9.3
* Adobe Acrobat Professional 9.2
* Adobe Acrobat Professional 9.1
* Adobe Acrobat Professional 10.1
* Adobe Acrobat Professional 10.0.3
* Adobe Acrobat Professional 10.0.2
* Adobe Acrobat Professional 10.0.1
* Adobe Acrobat Professional 10.0
* Adobe Acrobat 10.1.1
* Adobe Acrobat 9.4.6
* Adobe Acrobat 9.3.3
* Adobe Acrobat 9.3.3
* Adobe Acrobat 9.3.2
* Adobe Acrobat 9.3.1
* Adobe Acrobat 9.1.1
* Adobe Acrobat 8.2.4
* Adobe Acrobat 9.4.5
* Adobe Acrobat 9.4.4
* Adobe Acrobat 9.4.3
* Adobe Acrobat 9.4.2
* Adobe Acrobat 9.4.1
* Adobe Acrobat 9.4
* Adobe Acrobat 9.3
* Adobe Acrobat 9.2
* Adobe Acrobat 9
* Adobe Acrobat 10.1
* Adobe Acrobat 10.0.3
* Adobe Acrobat 10.0.2
* Adobe Acrobat 10.0.1
* Adobe Acrobat 10.0
Immune Systems:
* Adobe Reader 10.1.2
* Adobe Reader 9.4.7
* Adobe Reader 9.5
* Adobe Acrobat Standard 10.1.2
* Adobe Acrobat Standard 9.4.7
* Adobe Acrobat Standard 9.5
* Adobe Acrobat Professional 10.1.2
* Adobe Acrobat Professional 9.4.7
* Adobe Acrobat Professional 9.5
* Adobe Acrobat 10.1.2
* Adobe Acrobat 9.4.7
* Adobe Acrobat 9.5
Adobe Acrobat and Reader are prone to a remote memory corruption vulnerability. Attackers can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely cause denial-of-service conditions.
Vendor Status:
Adobe as issued an update for this vulnerablity.