CVE-2011-4369

High PUBLISHED

Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6...

Adobe · Reader and Acrobat

Not yet in CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
10.0 High

At a Glance

Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6 on Mac OS X, Adobe Reader and Acrobat 10.x through 10.1.1 on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.

windows macos
CVE Published
Dec 16, 2011
Exploitation Reported
Dec 16, 2011
CVSS
10.0 High
EPSS
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • openSUSE-SU-2012:0087 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00020...
  • RHSA-2012:0011 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2012-0011.html
  • SUSE-SU-2012:0086 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00019...
  • TA11-350A us-cert.gov · Third-Party Advisory http://www.us-cert.gov/cas/techalerts/TA11-350A.html
  • oval:org.mitre.oval:def:14865 oval.cisecurity.org · VDB Entry https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.m...
Show 3 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.