CVE-2014-8454: Use After Free
Published Dec 10, 2014
·Updated
Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8455 and CVE-2014-9165.
Affected Software
56 affected components
Adobe Acrobat=10.0
Adobe Acrobat=10.0.1
Adobe Acrobat=10.0.2
Adobe Acrobat=10.0.3
Adobe Acrobat=10.1
Adobe Acrobat=10.1.1
Adobe Acrobat=10.1.2
Adobe Acrobat=10.1.3
Adobe Acrobat=10.1.4
Adobe Acrobat=10.1.5
Adobe Acrobat=10.1.6
Adobe Acrobat=10.1.7
Adobe Acrobat=10.1.8
Adobe Acrobat=10.1.9
Adobe Acrobat=10.1.10
Adobe Acrobat=10.1.11
Adobe Acrobat=10.1.12
Adobe Acrobat=11.0
Adobe Acrobat=11.0.1
Adobe Acrobat=11.0.2
Adobe Acrobat=11.0.3
Adobe Acrobat=11.0.4
Adobe Acrobat=11.0.5
Adobe Acrobat=11.0.6
Adobe Acrobat=11.0.7
Adobe Acrobat=11.0.8
Adobe Acrobat=11.0.9
Apple iOS and macOS
Microsoft Windows
Adobe Acrobat Reader=10.0
Adobe Acrobat Reader=10.0.1
Adobe Acrobat Reader=10.0.2
Adobe Acrobat Reader=10.0.3
Adobe Acrobat Reader=10.1
Adobe Acrobat Reader=10.1.1
Adobe Acrobat Reader=10.1.2
Adobe Acrobat Reader=10.1.3
Adobe Acrobat Reader=10.1.4
Adobe Acrobat Reader=10.1.5
Adobe Acrobat Reader=10.1.6
Adobe Acrobat Reader=10.1.7
Adobe Acrobat Reader=10.1.8
Adobe Acrobat Reader=10.1.9
Adobe Acrobat Reader=10.1.10
Adobe Acrobat Reader=10.1.11
Adobe Acrobat Reader=10.1.12
Adobe Acrobat Reader=11.0.0
Adobe Acrobat Reader=11.0.01
Adobe Acrobat Reader=11.0.02
Adobe Acrobat Reader=11.0.03
Adobe Acrobat Reader=11.0.04
Adobe Acrobat Reader=11.0.05
Adobe Acrobat Reader=11.0.06
Adobe Acrobat Reader=11.0.07
Adobe Acrobat Reader=11.0.08
Adobe Acrobat Reader=11.0.09
Event History
Dec 10, 2014
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8454?
CVE-2014-8454 is rated as a critical vulnerability, allowing attackers to execute arbitrary code.
2
How do I fix CVE-2014-8454?
CVE-2014-8454 can be fixed by updating Adobe Reader and Acrobat to the latest version provided by Adobe.
3
What software versions are affected by CVE-2014-8454?
CVE-2014-8454 affects Adobe Reader and Acrobat versions 10.x before 10.1.13 and 11.x before 11.0.10.
4
What kinds of attacks can occur due to CVE-2014-8454?
CVE-2014-8454 can be exploited to allow remote attackers to execute arbitrary code on the affected systems.
5
Is this vulnerability present on both Windows and macOS?
Yes, CVE-2014-8454 affects both Windows and macOS versions of Adobe Reader and Acrobat.