Vulnerability Description
Adobe Reader 11.0.06 allows attackers to bypass a PDF sandbox protection mechanism via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Acrobat Reader | 11.0.6 |
Related Weaknesses (CWE)
References
- http://helpx.adobe.com/security/products/reader/apsb14-15.html
- http://twitter.com/thezdi/statuses/443827076580122624
- http://www.pwn2own.com/2014/03/pwn2own-results-for-wednesday-day-one/
- http://helpx.adobe.com/security/products/reader/apsb14-15.html
- http://twitter.com/thezdi/statuses/443827076580122624
- http://www.pwn2own.com/2014/03/pwn2own-results-for-wednesday-day-one/
FAQ
What is CVE-2014-0512?
CVE-2014-0512 is a vulnerability with a CVSS score of 10.0 (HIGH). Adobe Reader 11.0.06 allows attackers to bypass a PDF sandbox protection mechanism via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.
How severe is CVE-2014-0512?
CVE-2014-0512 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-0512?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Acrobat Reader.