CVE-2009-2993
The JavaScript for Acrobat API in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 does not properly implement the (1) Privileged Context and (2) Safe Path restrictions for unspecified JavaScript methods, which allows…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The JavaScript for Acrobat API in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 does not properly implement the (1) Privileged Context and (2) Safe Path restrictions for unspecified JavaScript methods, which allows remote attackers to create arbitrary files, and possibly execute arbitrary code, via the cPath parameter in a crafted PDF file. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 6.73% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- adobe/acrobat · adobe/acrobat reader
- Source
- cve@mitre.org
References
- http://securitytracker.com/id?1023007
- http://www.adobe.com/support/security/bulletins/apsb09-15.htmlPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/257117Patch, US Government Resource
- http://www.securityfocus.com/bid/36638
- http://www.securityfocus.com/bid/36664
- http://www.us-cert.gov/cas/techalerts/TA09-286B.htmlPatch, US Government Resource
- http://www.vupen.com/english/advisories/2009/2898Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5822
- http://securitytracker.com/id?1023007
- http://www.adobe.com/support/security/bulletins/apsb09-15.htmlPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/257117Patch, US Government Resource
- http://www.securityfocus.com/bid/36638
- http://www.securityfocus.com/bid/36664
- http://www.us-cert.gov/cas/techalerts/TA09-286B.htmlPatch, US Government Resource
- http://www.vupen.com/english/advisories/2009/2898Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5822
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.