CVE-2013-5325: Adobe Acrobat

High severity, CVSS 9.3. EPSS: 3.6% chance of exploitation in the next 30 days.

Adobe Reader and Acrobat 11.x before 11.0.05 on Windows allow remote attackers to execute arbitrary JavaScript code in a javascript: URL via a crafted PDF document.

Affected products

  • Adobe Acrobat: version 11.0 only; version 11.0.1 only; version 11.0.2 only; version 11.0.3 only; version 11.0.4 only
  • Adobe Acrobat Reader: version 11.0 only; version 11.0.1 only; version 11.0.2 only; version 11.0.3 only; version 11.0.4 only

Published 2013-10-09. Last modified 2026-06-16.