Adobe Reader < 9.4.7 Multiple Memory Corruption Vulnerabilities (APSB11-30)

High Nessus Plugin ID 57043


The version of Adobe Reader on the remote Windows host is affected by multiple memory corruption vulnerabilities.


The remote Windows host contains a version of Adobe Reader earlier than 9.4.7. Such versions are affected by multiple memory corruption vulnerabilities related to the 'Universal 3D' (U3D) file format and the 'Product Representation Compact' (PRC) component.

A remote attacker could exploit this by tricking a user into viewing a maliciously crafted PDF file, causing application crashes and potentially resulting in arbitrary code execution.

This plugin does not check for Reader 10.x releases, which are vulnerable but were not fixed until APSB12-01. Refer to plugin 57484 for more information.


Upgrade to Adobe Reader 9.4.7 or later.

See Also

Plugin Details

Severity: High

ID: 57043

File Name: adobe_reader_apsa11-04.nasl

Version: $Revision: 1.22 $

Type: local

Agent: windows

Family: Windows

Published: 2011/12/07

Modified: 2017/12/15

Dependencies: 20836

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:H/RL:OF/RC:ND

Vulnerability Information

CPE: cpe:/a:adobe:acrobat_reader

Required KB Items: SMB/Acroread/Version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2011/12/16

Vulnerability Publication Date: 2011/12/06

Exploitable With


Core Impact

Metasploit (Adobe Reader U3D Memory Corruption Vulnerability)

Reference Information

CVE: CVE-2011-2462, CVE-2011-4369

BID: 50922, 51092

OSVDB: 77529, 78026