LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2013-3346: Adobe Reader and Acrobat Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2013-3346 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service.

CVE-2013-3346 is a memory corruption vulnerability in Adobe Reader and Acrobat. According to CISA, it can allow attackers to execute arbitrary code or cause a denial of service. For IT and security teams, this matters because PDF readers are widely deployed on endpoints and often process untrusted files from email or the web, giving a successful exploit a direct path to user-context code execution.

Public detail is limited to the CISA summary and the CWE classification; confirm exact affected builds, fixed versions, and any platform notes against the vendor advisory before acting.

How it works

The weakness is classified as CWE-119 (improper restriction of operations within the bounds of a memory buffer). In products of this class, memory corruption typically occurs when the application mishandles crafted input—here, a malicious PDF or related document—so that attacker-controlled data overwrites adjacent memory. That can crash the process (denial of service) or, if the corruption is steered carefully, divert control flow to attacker-supplied code running with the privileges of the user who opened the file.

No exploit mechanics, proof-of-concept details, or specific trigger conditions are provided in the available facts. Treat any PDF or Acrobat-related content from untrusted sources as a potential vector until the environment is patched, and rely on the vendor advisory for precise technical description.

Am I affected? How to find it in your systems

Adobe Reader and Acrobat commonly run on Windows and macOS workstations, VDI images, and any system where users open PDFs. Inventory steps:

Telemetry signs of exploitation for this class are generic: unexpected Reader/Acrobat crashes, faulting module entries in Windows Error Reporting or macOS crash logs, or process launches of the PDF application followed by unusual child processes or network connections. There is no documented ransomware use associated with this CVE in the given facts, so do not treat ransomware-specific IOCs as confirmed for this issue.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Obtain the security update that addresses CVE-2013-3346 from Adobe, test in a representative group, then deploy to all systems running Reader or Acrobat. After installation, verify the version string matches the fixed build listed in the advisory.

Additional hardening appropriate to this product class:

If you can't patch immediately

Until the vendor update is applied, reduce risk with compensating controls:

These measures lower likelihood and impact but do not eliminate the vulnerability; schedule the official update as soon as practicable.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to endpoint compromise and subsequent data theft. The facts do not document ransomware use for CVE-2013-3346, but any confirmed code execution should trigger standard incident response: isolate the host, preserve volatile evidence, and hunt for lateral movement or exfiltration. As a quick personal check, users can run a free exposure scan of their email addresses against known breach datasets to see whether their credentials or personal data have appeared in prior incidents, then reset passwords and enable multi-factor authentication where exposure is found.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · Reader and Acrobat
WeaknessCWE-119
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities