CVE-2011-2462
adobe acrobat, adobe acrobat reader
Published 7 Dec 2011 · updated 16 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 8 Jun 2022, with a remediation deadline of 22 Jun 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.
References
- lists.opensuse.org/opensuse-security-announce/2012-01/msg00019.html · Broken Link
- lists.opensuse.org/opensuse-security-announce/2012-01/msg00020.html · Broken Link
- www.adobe.com/support/security/advisories/apsa11-04.html · Vendor Advisory
- www.adobe.com/support/security/bulletins/apsb11-30.html · Not Applicable
- www.adobe.com/support/security/bulletins/apsb12-01.html · Not Applicable
- www.redhat.com/support/errata/RHSA-2012-0011.html · Broken Link
- www.us-cert.gov/cas/techalerts/TA11-350A.html · Third Party Advisory, US Government Resource
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14562 · Broken Link
- github.com/cisagov/vulnrichment/issues/199 · Issue Tracking
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-2462 · US Government Resource