CVE-2009-1862
Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 25.01% probability · 98th percentile
- CISA KEV
- Listed 8 June 2022 · due 22 June 2022
- Weakness
- CWE-787
- Affected
- adobe/acrobat · adobe/acrobat reader · adobe/flash player
- Source
- cve@mitre.org
CISA notes
For Adobe Acrobat and Reader, apply updates per vendor instructions. For Adobe Flash Player, the impacted product is end-of-life and should be disconnected if still in use. https://nvd.nist.gov/vuln/detail/CVE-2009-1862
References
- http://blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.htmlBroken Link, Vendor Advisory
- http://bugs.adobe.com/jira/browse/FP-1265Broken Link
- http://isc.sans.org/diary.html?storyid=6847Not Applicable
- http://lists.apple.com/archives/security-announce/2009/Sep/msg00003.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.htmlMailing List, Third Party Advisory
- http://news.cnet.com/8301-27080_3-10293389-245.htmlBroken Link
- http://secunia.com/advisories/36193Broken Link
- http://secunia.com/advisories/36374Broken Link
- http://secunia.com/advisories/36701Broken Link
- http://security.gentoo.org/glsa/glsa-200908-04.xmlThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1Broken Link
- http://support.apple.com/kb/HT3864Third Party Advisory
- http://support.apple.com/kb/HT3865Third Party Advisory
- http://www.adobe.com/support/security/advisories/apsa09-03.htmlVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb09-10.htmlNot Applicable
- http://www.adobe.com/support/security/bulletins/apsb09-13.htmlNot Applicable
- http://www.kb.cert.org/vuls/id/259425Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/35759Broken Link, Third Party Advisory, VDB Entry
- http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-072209-2512-99Broken Link
- http://www.symantec.com/connect/blogs/next-generation-flash-vulnerabilityBroken Link
- http://blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.htmlBroken Link, Vendor Advisory
- http://bugs.adobe.com/jira/browse/FP-1265Broken Link
- http://isc.sans.org/diary.html?storyid=6847Not Applicable
- http://lists.apple.com/archives/security-announce/2009/Sep/msg00003.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.htmlMailing List, Third Party Advisory
- http://news.cnet.com/8301-27080_3-10293389-245.htmlBroken Link
- http://secunia.com/advisories/36193Broken Link
- http://secunia.com/advisories/36374Broken Link
- http://secunia.com/advisories/36701Broken Link
- http://security.gentoo.org/glsa/glsa-200908-04.xmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.