LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2014-0546: Adobe Reader and Acrobat Sandbox Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2014-0546 to its Known Exploited Vulnerabilities catalog on May 25, 2022, with a federal patch deadline of Jun 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context.

CVE-2014-0546 is a sandbox bypass vulnerability in Adobe Reader and Acrobat on Windows. It allows an attacker to escape the product’s sandbox protections and run native code in a privileged context. For IT and security teams, this matters because PDF viewers are widely deployed and often process untrusted documents; a successful bypass can turn a document-based attack into broader host compromise. Confirm all version and patch details against the vendor advisory.

How it works

Public detail on the exact weakness class (CWE) is limited. Per the available summary, Adobe Reader and Acrobat on Windows implement a sandbox intended to constrain what the application can do when rendering or handling content. This vulnerability allows that protection mechanism to be bypassed, so that code execution that should remain restricted can instead run with higher privilege on the host.

In practical terms, an attacker would typically need the user to open a crafted PDF or related content in an affected Reader or Acrobat instance. Once the sandbox is bypassed, the attacker can execute native code outside the intended isolation boundary. Exact exploit mechanics are not provided in the given facts; treat any public proof-of-concept claims cautiously and validate behavior only in controlled lab conditions against vendor guidance.

Am I affected? How to find it in your systems

Adobe Reader and Acrobat commonly run on Windows endpoints used for document review, email attachments, web downloads, and shared file workflows. Inventory every system that has these products installed, including VDI images, jump hosts, and kiosks.

If you cannot confirm the exact build, assume potential exposure until you match it to the vendor’s fixed list.

How to remediate

Patch first. Apply the updates Adobe published for this issue, following the vendor instructions referenced in the CISA-required action. Deploy through your standard software-update or package-management channel, then verify installation on a sample of endpoints.

If you can't patch immediately

Reduce exposure until the vendor update can be applied everywhere.

These steps do not replace the patch; they only buy time.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to host compromise and follow-on data theft, even when ransomware use is not documented for this CVE. If you suspect exploitation, isolate affected hosts, preserve memory and disk evidence, rotate credentials accessible from those systems, and begin incident scoping for lateral movement. As a further check on whether associated identities appear in known breach datasets, you can run a free exposure scan of your email against published breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · Reader and Acrobat
Added to CISA KEVMay 25, 2022
Federal patch deadlineJun 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities