CVE-2013-2729

CRITICAL(9.8)KEVLikely Exploited

Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability

Description

CVE-2013-2729 is a critical remote code execution vulnerability (CWE-190) in Adobe Reader and Acrobat caused by an integer overflow condition during the processing of specially crafted PDF files. An attacker can exploit this flaw by distributing a malicious PDF document that, when opened by the victim, triggers the integer overflow and enables arbitrary code execution with the privileges of the current user. CISA has confirmed active exploitation and added CVE-2013-2729 to the Known Exploited Vulnerabilities catalog. With an EPSS score of 89.1% (99.9th percentile), this vulnerability represents one of the most exploited PDF-based attack vectors.

KEV Information

Vendor
Adobe
Product
Reader and Acrobat
Date Added
March 28, 2022
Due Date
April 18, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
adobeacrobat>= 9.0, < 9.5.5; >= 10.0, < 10.1.7; >= 11.0, < 11.0.03
adobeacrobat reader>= 9.0, < 9.5.5; >= 10.0, < 10.1.7; >= 11.0, < 11.0.03
suselinux enterprise desktop10; 11
redhatenterprise linux desktop6.0
redhatenterprise linux eus5.9; 6.4
redhatenterprise linux server6.0
redhatenterprise linux server aus5.9; 6.4
redhatenterprise linux workstation6.0

Multiple CVSS Assessments

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-190: Integer Overflow or Wraparound

CWE-190 describes a weakness where an integer value is incremented to a value that is too large to store in the associated representation, causing the value to wrap around and produce an unexpectedly small or negative number. In CVE-2013-2729, Adobe Reader and Acrobat encounter an integer overflow during PDF processing that leads to an undersized memory allocation, which is subsequently overflowed with attacker-controlled data, enabling arbitrary code execution.

Learn more: CWE-190 — Integer Overflow or Wraparound

Impact Analysis

CVE-2013-2729 is exploitable by distributing a malicious PDF file via email, web download, or file sharing, requiring only that the victim opens the document in Adobe Reader or Acrobat. Successful exploitation grants the attacker code execution with the privileges of the user running the PDF reader, which in most environments provides access to the user's files, email, browser data, and network resources. Confidentiality is fully compromised as the attacker can exfiltrate any data accessible to the victim. Integrity and availability are equally impacted through malware deployment, data manipulation, and potential ransomware installation. The 99.9th percentile EPSS score reflects that this vulnerability has been extensively weaponized and used in large-scale attack campaigns.

Exploit Maturity

CVE-2013-2729 is confirmed as actively exploited in the wild by CISA and is listed in the Known Exploited Vulnerabilities catalog. The EPSS score of 89.1% (99.9th percentile) indicates near-certain real-world exploitation, and this vulnerability has been integrated into multiple exploit kits and used in widespread malicious PDF campaigns. PDF-based exploits are particularly effective because PDF is a universally trusted document format, and many users open PDF attachments without suspicion.

Remediation

  1. Update Adobe Reader and Acrobat to the latest patched versions immediately, applying Adobe Security Bulletin APSB13-15 (May 2013) to address CVE-2013-2729.
  2. Enable Protected Mode (sandboxing) in Adobe Reader and Acrobat to limit the impact of exploitation by restricting the compromised process's access to the operating system.
  3. Deploy email and web gateway filtering to scan incoming PDF files for known exploit signatures and malicious content before they reach end users.
  4. Consider migrating to alternative PDF readers with enhanced security features or using browser-based PDF rendering, which provides additional sandboxing protections.
  5. Educate users about the risks of opening unsolicited PDF attachments and implement organizational policies requiring verification of unexpected documents from external sources.

Technical Details

CVE-2013-2729 is an integer overflow vulnerability (CWE-190) in Adobe Reader and Acrobat that occurs during the processing of a specially crafted BMP-compressed data stream embedded within a PDF file. When the PDF parser calculates the size of a memory buffer based on attacker-controlled image dimension values, the multiplication overflows, resulting in an undersized heap allocation. The subsequent write operation then copies more data into the buffer than was allocated, causing a classic heap buffer overflow. The attacker can control the overflow data to overwrite adjacent heap metadata or objects, enabling them to hijack program execution flow. By combining this with heap spraying techniques to place shellcode at predictable memory addresses, the attacker achieves reliable arbitrary code execution within the Adobe Reader process.

Frequently Asked Questions

Is CVE-2013-2729 being actively exploited?

Yes. CVE-2013-2729 is confirmed as actively exploited in the wild and is listed in the CISA KEV catalog. The EPSS score of 89.1% (99.9th percentile) reflects near-certain exploitation activity, and the vulnerability has been integrated into multiple exploit kits for widespread PDF-based attacks.

What products are affected by CVE-2013-2729?

CVE-2013-2729 affects Adobe Reader and Acrobat versions 9.x through 9.5.4, 10.x through 10.1.6, and 11.x through 11.0.02 on both Windows and macOS platforms.

How do I fix CVE-2013-2729?

Update Adobe Reader and Acrobat to the latest versions per Adobe Security Bulletin APSB13-15 (May 2013). Enable Protected Mode in Adobe Reader for additional sandboxing protection, and deploy email filtering to block malicious PDFs.

How severe is CVE-2013-2729?

CVE-2013-2729 is rated CRITICAL and enables full remote code execution through a malicious PDF document. The 99.9th percentile EPSS score and CISA KEV listing confirm this is one of the most extensively exploited PDF-based vulnerabilities, requiring urgent remediation.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score66.55%
EPSS Percentile99.2%

Dates

PublishedMay 16, 2013
Last ModifiedJune 16, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.