CVE-2014-0546: Adobe Reader and Acrobat Sandbox Bypass Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-05-25. EPSS: 22.3% chance of exploitation in the next 30 days.
Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via unspecified vectors.
Affected products
- Adobe Acrobat: from 10.0, before 10.1.11 (fixed in 10.1.11); from 11.0, before 11.0.08 (fixed in 11.0.08)
- Adobe Acrobat Reader: from 10.0, before 10.1.11 (fixed in 10.1.11); from 11.0, before 11.0.08 (fixed in 11.0.08)
Published 2014-08-12. Last modified 2026-06-17.