SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-3956

The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecified impact and attack vectors, related to a "script injection…

HIGH 10.0EPSS 7.73%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (7.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecified impact and attack vectors, related to a "script injection vulnerability," as demonstrated by Acrobat Forms Data Format (FDF) behavior that allows cross-site scripting (XSS) by user-assisted remote attackers.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
7.73% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-16
Affected
adobe/acrobat · adobe/acrobat reader
Source
psirt@adobe.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.