CVE-2011-2462
Summary
| CVE | CVE-2011-2462 |
|---|---|
| State | PUBLISHED |
| Assigner | adobe |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-12-07 19:55:01 UTC |
| Updated | 2026-04-21 21:13:14 UTC |
| Description | Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.863190000 probability, percentile 0.997160000 (date 2026-07-22)
CISA KEV: Listed on 2022-06-08; due 2022-06-22; ransomware use Unknown
Problem Types: CWE-787 | n/a | CWE-787 CWE-787 Out-of-bounds Write
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | ADP | DECLARED | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
CISA Known Exploited Vulnerability
| Vendor | Adobe |
|---|---|
| Product | Reader and Acrobat |
| Name | Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2011-2462 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Acrobat | All | All | All | All |
| Application | Adobe | Acrobat Reader | All | All | All | All |
| Application | Adobe | Acrobat Reader | All | All | All | All |
| Operating System | Apple | Mac Os X | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Operating System | Opengroup | Unix | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Adobe - Security Bulletins: APSB12-01 - Prenotification Security Advisory for Adobe Reader and Acrobat | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Not Applicable |
| US-CERT Technical Cyber Security Alert TA11-350A -- Adobe Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | Third Party Advisory, US Government Resource |
| [security-announce] SUSE-SU-2012:0086-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Broken Link |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link |
| Adobe Security Advisories: APSA11-04 - Security Advisory for Adobe Reader and Acrobat | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Vendor Advisory |
| [security-announce] openSUSE-SU-2012:0087-1: important: acroread | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Broken Link |
| github.com/cisagov/vulnrichment/issues/199 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | github.com | Issue Tracking |
| Adobe - Security Bulletins: APSB11-30 - Security updates available for Adobe Reader and Acrobat | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Not Applicable |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.