peter bassill · operator
$ cve CVE-2009-1862 JSON

CVE-2009-1862 KEV

7.8
HIGH · CVSS 3.1 · EPSS 21.2% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-22.

Description

Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS21.2% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-787
On CISA KEVyes — remediate by 2022-06-22
Public exploitnone known
Published2009-07-23
Last modified2026-06-16

CISA KEV

NameAdobe Acrobat and Reader, Flash Player Unspecified Vulnerability
Added2022-06-08
Due2022-06-22
Vendor / productAdobe / Acrobat and Reader, Flash Player
Ransomware usenone reported

Affected (3)

VendorProduct
adobeacrobat
adobeacrobat reader
adobeflash player

References

→ the Explorer  ·  watch your stack  ·  NVD