SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2009-1862

Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability

KEVHIGH 7.8EPSS 25.0%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
25.01% probability · 98th percentile
CISA KEV
Listed 8 June 2022 · due 22 June 2022
Weakness
CWE-787
Affected
adobe/acrobat · adobe/acrobat reader · adobe/flash player
Source
cve@mitre.org

CISA notes

For Adobe Acrobat and Reader, apply updates per vendor instructions. For Adobe Flash Player, the impacted product is end-of-life and should be disconnected if still in use. https://nvd.nist.gov/vuln/detail/CVE-2009-1862

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.