Adobe Acrobat < 10.1.12 / 11.0.09 Multiple Vulnerabilities (APSB14-20)

High Nessus Plugin ID 77711


The version of Adobe Acrobat on the remote Windows host is affected by multiple vulnerabilities.


The version of Adobe Acrobat installed on the remote host is a version prior to 10.1.12 / 11.0.09. It is, therefore, affected by the following vulnerabilities :

- A use-after-free error exists that allows arbitrary code execution. (CVE-2014-0560)

- A heap-based buffer overflow exists that allows arbitrary code execution. (CVE-2014-0561, CVE-2014-0567)

- A memory corruption error exists that allows denial of service attacks. (CVE-2014-0563)

- Memory corruption errors exist that allows arbitrary code execution. (CVE-2014-0565, CVE-2014-0566)

- An unspecified error exists that allows the bypassing of the sandbox security restrictions. (CVE-2014-0568)

- A race condition exists in the 'MoveFileEx' call hook feature that allows attackers to bypass the sandbox protection mechanism to write files to arbitrary locations. Note that this issue only affects Adobe Acrobat 11.x. This issue has not been officially fixed in APSB14-20; however, it is unlikely to be exploitable due to a related defense-in-depth change in version 11.0.09. (CVE-2014-9150)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.


Upgrade to Adobe Acrobat 10.1.12 / 11.0.09 or later.

See Also

Plugin Details

Severity: High

ID: 77711

File Name: adobe_acrobat_apsb14-20.nasl

Version: $Revision: 1.10 $

Type: local

Agent: windows

Family: Windows

Published: 2014/09/16

Modified: 2017/04/27

Dependencies: 40797

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 7.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:ND

Vulnerability Information

CPE: cpe:/a:adobe:acrobat

Required KB Items: SMB/Registry/Enumerated, installed_sw/Adobe Acrobat

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2014/09/16

Vulnerability Publication Date: 2014/09/16

Reference Information

CVE: CVE-2014-0560, CVE-2014-0561, CVE-2014-0563, CVE-2014-0565, CVE-2014-0566, CVE-2014-0567, CVE-2014-0568, CVE-2014-9150

BID: 69823, 69821, 69826, 69824, 69825, 69827, 69828, 71366

OSVDB: 111533, 111536, 111535, 111538, 111539, 111537, 111540