VulnerabilityAnalyzed
CVE-2009-4324
Adobe Acrobat and Reader Use-After-Free Vulnerability
KEVHIGH 7.8EPSS 81.9%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 81.93% probability · 100th percentile
- CISA KEV
- Listed 8 June 2022 · due 22 June 2022
- Weakness
- CWE-416
- Affected
- adobe/acrobat · adobe/acrobat reader · suse/linux enterprise debuginfo · opensuse/opensuse · suse/linux enterprise
- Source
- psirt@adobe.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2009-4324
References
- http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.htmlBroken Link, Vendor Advisory
- http://contagiodump.blogspot.com/2009/12/virustotal-httpwww.htmlExploit, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.htmlMailing List, Third Party Advisory
- http://osvdb.org/60980Broken Link
- http://secunia.com/advisories/37690Broken Link, Vendor Advisory
- http://secunia.com/advisories/38138Broken Link, Vendor Advisory
- http://secunia.com/advisories/38215Broken Link, Vendor Advisory
- http://www.adobe.com/support/security/advisories/apsa09-07.htmlVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb10-02.htmlNot Applicable
- http://www.kb.cert.org/vuls/id/508357Third Party Advisory, US Government Resource
- http://www.metasploit.com/redmine/projects/framework/repository/revisions/7881/entry/modules/exploits/windows/fileformat/adobe_media_newplayer.rbBroken Link
- http://www.redhat.com/support/errata/RHSA-2010-0060.htmlBroken Link
- http://www.securityfocus.com/bid/37331Broken Link, Third Party Advisory, VDB Entry
- http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214Broken Link
- http://www.symantec.com/connect/blogs/zero-day-xmas-presentBroken Link
- http://www.us-cert.gov/cas/techalerts/TA10-013A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2009/3518Broken Link, Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0103Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=547799Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54747Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6795Broken Link
- http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.htmlBroken Link, Vendor Advisory
- http://contagiodump.blogspot.com/2009/12/virustotal-httpwww.htmlExploit, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.htmlMailing List, Third Party Advisory
- http://osvdb.org/60980Broken Link
- http://secunia.com/advisories/37690Broken Link, Vendor Advisory
- http://secunia.com/advisories/38138Broken Link, Vendor Advisory
- http://secunia.com/advisories/38215Broken Link, Vendor Advisory
- http://www.adobe.com/support/security/advisories/apsa09-07.htmlVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb10-02.htmlNot Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.