10

CVE-2014-0568

The NtSetInformationFile system call hook feature in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows allows attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via an NTFS junction attack.

Data is provided by the National Vulnerability Database (NVD)
AdobeAcrobat Reader Version10.0
   MicrosoftWindows
AdobeAcrobat Reader Version10.0.1
   MicrosoftWindows
AdobeAcrobat Reader Version10.0.2
   MicrosoftWindows
AdobeAcrobat Reader Version10.0.3
   MicrosoftWindows
AdobeAcrobat Reader Version10.1
   MicrosoftWindows
AdobeAcrobat Reader Version10.1.1
   MicrosoftWindows
AdobeAcrobat Reader Version10.1.2
   MicrosoftWindows
AdobeAcrobat Reader Version10.1.3
   MicrosoftWindows
AdobeAcrobat Reader Version10.1.4
   MicrosoftWindows
AdobeAcrobat Reader Version10.1.5
   MicrosoftWindows
AdobeAcrobat Reader Version10.1.6
   MicrosoftWindows
AdobeAcrobat Reader Version10.1.7
   MicrosoftWindows
AdobeAcrobat Reader Version10.1.8
   MicrosoftWindows
AdobeAcrobat Reader Version10.1.9
   MicrosoftWindows
AdobeAcrobat Reader Version10.1.10
   MicrosoftWindows
AdobeAcrobat Reader Version10.1.11
   MicrosoftWindows
AdobeAcrobat Reader Version11.0
   MicrosoftWindows
AdobeAcrobat Reader Version11.0.1
   MicrosoftWindows
AdobeAcrobat Reader Version11.0.2
   MicrosoftWindows
AdobeAcrobat Reader Version11.0.3
   MicrosoftWindows
AdobeAcrobat Reader Version11.0.4
   MicrosoftWindows
AdobeAcrobat Reader Version11.0.5 Update- SwPlatformwindows
   MicrosoftWindows
AdobeAcrobat Reader Version11.0.6
   MicrosoftWindows
AdobeAcrobat Reader Version11.0.7
   MicrosoftWindows
AdobeAcrobat Reader Version11.0.8
   MicrosoftWindows
AdobeAcrobat Version10.0
   MicrosoftWindows
AdobeAcrobat Version10.0 Update- Editionpro
   MicrosoftWindows
AdobeAcrobat Version10.0.1
   MicrosoftWindows
AdobeAcrobat Version10.0.1 Update- Editionpro
   MicrosoftWindows
AdobeAcrobat Version10.0.2
   MicrosoftWindows
AdobeAcrobat Version10.0.3
   MicrosoftWindows
AdobeAcrobat Version10.1
   MicrosoftWindows
AdobeAcrobat Version10.1.1
   MicrosoftWindows
AdobeAcrobat Version10.1.2
   MicrosoftWindows
AdobeAcrobat Version10.1.3
   MicrosoftWindows
AdobeAcrobat Version10.1.4
   MicrosoftWindows
AdobeAcrobat Version10.1.5
   MicrosoftWindows
AdobeAcrobat Version10.1.6
   MicrosoftWindows
AdobeAcrobat Version10.1.7
   MicrosoftWindows
AdobeAcrobat Version10.1.8
   MicrosoftWindows
AdobeAcrobat Version10.1.9
   MicrosoftWindows
AdobeAcrobat Version10.1.10
   MicrosoftWindows
AdobeAcrobat Version10.1.11
   MicrosoftWindows
AdobeAcrobat Version11.0
   MicrosoftWindows
AdobeAcrobat Version11.0.1
   MicrosoftWindows
AdobeAcrobat Version11.0.2
   MicrosoftWindows
AdobeAcrobat Version11.0.3
   MicrosoftWindows
AdobeAcrobat Version11.0.4
   MicrosoftWindows
AdobeAcrobat Version11.0.5 Update- SwPlatformwindows
   MicrosoftWindows
AdobeAcrobat Version11.0.6
   MicrosoftWindows
AdobeAcrobat Version11.0.7
   MicrosoftWindows
AdobeAcrobat Version11.0.8
   MicrosoftWindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.36% 0.9
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C