Adobe Reader < 10.1.12 / 11.0.09 Multiple Vulnerabilities (APSB14-20)

High Nessus Plugin ID 77712


The version of Adobe Reader on the remote Windows host is affected by multiple vulnerabilities.


The version of Adobe Reader installed on the remote host is a version prior to 10.1.12 / 11.0.09. It is, therefore, affected by the following vulnerabilities :

- A use-after-free error exists that allows arbitrary code execution. (CVE-2014-0560)

- A heap-based buffer overflow exists that allows arbitrary code execution. (CVE-2014-0561, CVE-2014-0567)

- A memory corruption error exists that allows denial of service attacks. (CVE-2014-0563)

- Memory corruption errors exist that allows arbitrary code execution. (CVE-2014-0565, CVE-2014-0566)

- An unspecified error exists that allows the bypassing of the sandbox security restrictions. (CVE-2014-0568)

- A race condition exists in the 'MoveFileEx' call hook feature that allows attackers to bypass the sandbox protection mechanism to write files to arbitrary locations. Note that this issue only affects Adobe Reader 11.x. This issue has not been officially fixed in APSB14-20; however, it is unlikely to be exploitable due to a related defense-in-depth change in version 11.0.09. (CVE-2014-9150)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.


Upgrade to Adobe Reader 10.1.12 / 11.0.09 or later.

See Also

Plugin Details

Severity: High

ID: 77712

File Name: adobe_reader_apsb14-20.nasl

Version: $Revision: 1.10 $

Type: local

Agent: windows

Family: Windows

Published: 2014/09/16

Modified: 2017/04/27

Dependencies: 20836

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 7.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:ND

Vulnerability Information

CPE: cpe:/a:adobe:acrobat_reader

Required KB Items: SMB/Registry/Enumerated, installed_sw/Adobe Reader

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2014/09/16

Vulnerability Publication Date: 2014/09/16

Reference Information

CVE: CVE-2014-0560, CVE-2014-0561, CVE-2014-0563, CVE-2014-0565, CVE-2014-0566, CVE-2014-0567, CVE-2014-0568, CVE-2014-9150

BID: 69823, 69821, 69826, 69824, 69825, 69827, 69828, 71366

OSVDB: 111533, 111536, 111535, 111538, 111539, 111537, 111540