First published: Wed May 14 2014(Updated: )
Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | =10.0 | |
Adobe Acrobat Reader | =10.0.1 | |
Adobe Acrobat Reader | =10.0.2 | |
Adobe Acrobat Reader | =10.0.3 | |
Adobe Acrobat Reader | =10.1 | |
Adobe Acrobat Reader | =10.1.1 | |
Adobe Acrobat Reader | =10.1.2 | |
Adobe Acrobat Reader | =10.1.3 | |
Adobe Acrobat Reader | =10.1.4 | |
Adobe Acrobat Reader | =10.1.5 | |
Adobe Acrobat Reader | =10.1.6 | |
Adobe Acrobat Reader | =10.1.7 | |
Adobe Acrobat Reader | =10.1.8 | |
Adobe Acrobat Reader | =10.1.9 | |
Adobe Acrobat Reader | =11.0 | |
Adobe Acrobat Reader | =11.0.1 | |
Adobe Acrobat Reader | =11.0.2 | |
Adobe Acrobat Reader | =11.0.3 | |
Adobe Acrobat Reader | =11.0.4 | |
Adobe Acrobat | =11.0.5 | |
Adobe Acrobat Reader | =11.0.6 | |
Apple iOS and macOS | ||
Microsoft Windows | ||
Adobe Acrobat Reader Notification Manager | =10.0 | |
Adobe Acrobat Reader Notification Manager | =10.0.1 | |
Adobe Acrobat Reader Notification Manager | =10.0.2 | |
Adobe Acrobat Reader Notification Manager | =10.0.3 | |
Adobe Acrobat Reader Notification Manager | =10.1 | |
Adobe Acrobat Reader Notification Manager | =10.1.1 | |
Adobe Acrobat Reader Notification Manager | =10.1.2 | |
Adobe Acrobat Reader Notification Manager | =10.1.3 | |
Adobe Acrobat Reader Notification Manager | =10.1.4 | |
Adobe Acrobat Reader Notification Manager | =10.1.5 | |
Adobe Acrobat Reader Notification Manager | =10.1.6 | |
Adobe Acrobat Reader Notification Manager | =10.1.7 | |
Adobe Acrobat Reader Notification Manager | =10.1.8 | |
Adobe Acrobat Reader Notification Manager | =10.1.9 | |
Adobe Acrobat Reader Notification Manager | =11.0 | |
Adobe Acrobat Reader Notification Manager | =11.0.1 | |
Adobe Acrobat Reader Notification Manager | =11.0.2 | |
Adobe Acrobat Reader Notification Manager | =11.0.3 | |
Adobe Acrobat Reader Notification Manager | =11.0.4 | |
Adobe Acrobat Reader | =11.0.5 | |
Adobe Acrobat Reader Notification Manager | =11.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0527 is classified as a critical vulnerability due to its ability to allow attackers to execute arbitrary code.
To fix CVE-2014-0527, users should update Adobe Reader and Acrobat to version 10.1.10 or later for 10.x and 11.0.7 or later for 11.x.
Adobe Reader versions 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X are affected by CVE-2014-0527.
The potential impact of CVE-2014-0527 includes arbitrary code execution, which can lead to full system compromise.
While updating is the best solution, users can limit exposure by avoiding opening untrusted PDFs until the software is updated.