CVE-2009-4324 KEV EXPLOIT
7.8
HIGH · CVSS 3.1 · EPSS 81.9% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-22.
Description
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 81.88% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-416 |
| On CISA KEV | yes — remediate by 2022-06-22 |
| Public exploit | yes |
| Published | 2009-12-15 |
| Last modified | 2026-06-16 |
CISA KEV
| Name | Adobe Acrobat and Reader Use-After-Free Vulnerability |
|---|---|
| Added | 2022-06-08 |
| Due | 2022-06-22 |
| Vendor / product | Adobe / Acrobat and Reader |
| Ransomware use | none reported |
Affected (7)
| Vendor | Product |
|---|---|
| adobe | acrobat |
| adobe | acrobat reader |
| apple | mac os x |
| microsoft | windows |
| opensuse | opensuse |
| suse | linux enterprise |
| suse | linux enterprise debuginfo |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Adobe - 'Doc.media.newPlayer' Use-After-Free (Metasploit) (2) | 2010-09-25 |
| exploit-db | Adobe - 'Doc.media.newPlayer' Use-After-Free (Metasploit) (1) | 2010-04-30 |
| exploit-db | Adobe Reader / Acrobat - '.PDF' File Overflow | 2009-12-23 |
References
- http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html
- http://contagiodump.blogspot.com/2009/12/virustotal-httpwww.html
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html
- http://osvdb.org/60980
- http://secunia.com/advisories/37690
- http://secunia.com/advisories/38138
- http://secunia.com/advisories/38215
- http://www.adobe.com/support/security/advisories/apsa09-07.html
- http://www.adobe.com/support/security/bulletins/apsb10-02.html
- http://www.kb.cert.org/vuls/id/508357
- http://www.metasploit.com/redmine/projects/framework/repository/revisions/7881/entry/modules/exploits/windows/fileformat/adobe_media_newplayer.rb
- http://www.redhat.com/support/errata/RHSA-2010-0060.html
- http://www.securityfocus.com/bid/37331
- http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214
- http://www.symantec.com/connect/blogs/zero-day-xmas-present
- http://www.us-cert.gov/cas/techalerts/TA10-013A.html
- http://www.vupen.com/english/advisories/2009/3518
- http://www.vupen.com/english/advisories/2010/0103
- https://bugzilla.redhat.com/show_bug.cgi?id=547799
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54747
→ the Explorer · watch your stack · NVD