CVE-2014-0546
Adobe Acrobat 10.0 – 10.1.11
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2014-0546 is a critical-severity an unspecified weakness vulnerability in Adobe Acrobat. Its CVSS base score is 9.8 (Critical).
Operationally, ranked in the top 3% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox bypass vulnerability tracked as CVE-2014-0546. The flaw allows attackers to circumvent the sandbox protection mechanism and execute native code in a privileged context via unspecified vectors, carrying a CVSS 3.1 score of 9.8 reflecting network attack vector, low complexity, and no required privileges or user interaction.
An unauthenticated remote attacker can exploit the issue to escape the sandbox and achieve privileged native code execution on the target system. The published description provides no further constraints on the attack delivery method beyond the unspecified vectors.
Adobe's APSB14-19 security bulletin addresses the issue by releasing updated builds that correct the sandbox bypass in the affected Reader and Acrobat products on Windows; the same advisory is referenced by multiple vulnerability trackers. No information on observed in-the-wild exploitation is supplied in the source data.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2014-0577
Vulnerability Data
Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via unspecified vectors.
- CWE(s)
- KEV Date Added
- 25 May 2022
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.