Adobe Reader and Acrobat 9.4.7 security updates
Report ID: AD201112001
Date Published: 16 December 2011
Criticality: Critical
Compromise Type: remote-code-execution
Compromise From: remote
Affected Product/Component:
Adobe Reader X (10.1.1)
Adobe Reader 9.4.6
Adobe Acrobat X (10.1.1)
Adobe Acrobat 9.4.6
Summary
Security updates for Adobe Reader and Adobe Acrobat have been released to address two critical vulnerabilities found in the prior versions.
Detailed Description
Adobe has released security updates for Adobe Reader and Acrobat to address two critical vulnerabilities that could cause memory corruption in the U3D and PRC components, and lead to arbitrary code execution. There are reports on these vulnerabilities being exploited in the wild, targeting against Adobe Reader 9.x on Windows.
As a protection against potential exploit, users are recommended to update to Adobe Reader X (10.1.2) and/or Adobe Acrobat X (10.1.2). Users of Adobe Reader and Adobe Acrobat version 9.4.6 are recommended to update to version 9.4.7.
CVE Reference
CVE-2011-2462, CVE-2011-4369
Solution
Update to the latest version of applicable product:
Adobe Reader
Adobe Acrobat




