CVE-2013-5325: Code Injection
Published Oct 9, 2013
·Updated
Adobe Reader and Acrobat 11.x before 11.0.05 on Windows allow remote attackers to execute arbitrary JavaScript code in a javascript: URL via a crafted PDF document.
Affected Software
11 affected components
Adobe Acrobat=11.0
Adobe Acrobat=11.0.1
Adobe Acrobat=11.0.2
Adobe Acrobat=11.0.3
Adobe Acrobat=11.0.4
Adobe Acrobat reader=11.0
Adobe Acrobat reader=11.0.1
Adobe Acrobat reader=11.0.2
Adobe Acrobat reader=11.0.3
Adobe Acrobat reader=11.0.4
Microsoft Windows
Event History
Oct 9, 2013
CVE Published
via MITRE·02:44 PM
Data Sourced
via MITRE·02:44 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5325?
CVE-2013-5325 is classified as a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2013-5325?
To fix CVE-2013-5325, update Adobe Reader and Acrobat to version 11.0.05 or later.
3
What types of attacks can exploit CVE-2013-5325?
CVE-2013-5325 can be exploited through crafted PDF documents containing malicious JavaScript.
4
Which versions of Adobe software are affected by CVE-2013-5325?
CVE-2013-5325 affects Adobe Reader and Acrobat versions 11.0 through 11.0.4.
5
What are the risks associated with CVE-2013-5325?
Exploitation of CVE-2013-5325 could allow attackers to execute arbitrary code on the victim's machine.