Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Apsb11 30 | — | — | Dec 19, 2011 | Dec 7, 2011 |
| Adobe Apsb12 01 | — | — | Jan 26, 2012 | Dec 7, 2011 |
| Adobe Reader Apsb11 30 | — | — | Apr 12, 2012 | Dec 7, 2011 |
| Adobe Reader Apsb12 01 | — | — | Apr 12, 2012 | Dec 7, 2011 |
| Freebsd | — | Upgrade acroread9 | Dec 10, 2025 | Jan 26, 2012 |
| Gentoo Linux | — | Upgrade app-text/acroread. | Oct 30, 2017 | Dec 7, 2011 |
| Suse | — | Upgrade acroreadUpgrade acroread-fonts-zh_TWUpgrade acroread-fonts-koUpgrade acroread-cmapsUpgrade acroread-fonts-jaUpgrade acroread-fonts-zh_CN | Feb 17, 2015 | Dec 7, 2011 |
| Ubuntu | — | Upgrade acroread | Nov 19, 2024 | Dec 7, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub