CVE-2014-0562: XSS
Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on OS X allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0562?
CVE-2014-0562 has a severity rating that indicates it allows remote attackers to inject arbitrary web script or HTML into affected Adobe Reader and Acrobat versions.
How do I fix CVE-2014-0562?
To fix CVE-2014-0562, update Adobe Reader and Acrobat to version 10.1.12 or 11.0.09 or later.
What versions of Adobe Reader are affected by CVE-2014-0562?
CVE-2014-0562 affects Adobe Reader versions 10.x before 10.1.12 and 11.x before 11.0.09 on OS X.
What types of attacks can CVE-2014-0562 enable?
CVE-2014-0562 can enable cross-site scripting (XSS) attacks through the injection of malicious scripts.
Is my system vulnerable to CVE-2014-0562 if I use an up-to-date version of Adobe Reader?
If you are using an up-to-date version of Adobe Reader or Acrobat, you are not vulnerable to CVE-2014-0562.