peter bassill · operator
$ cve CVE-2010-1240 JSON

CVE-2010-1240 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 73.6% (pctl 99)

Patch early

A public exploit exists.

Description

Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to trick users into executing an arbitrary local program that was specified in a PDF document, as demonstrated by a text field that claims that the Open button will enable the user to read an encrypted message.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS73.62% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2010-04-05
Last modified2026-06-16

Affected (2)

VendorProduct
adobeacrobat reader
microsoftwindows

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD