CVE-2010-2862 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 16.3% (pctl 97)
Patch early
A public exploit exists.
Description
Integer overflow in CoolType.dll in Adobe Reader 8.2.3 and 9.3.3, and Acrobat 9.3.3, allows remote attackers to execute arbitrary code via a TrueType font with a large maxCompositePoints value in a Maximum Profile (maxp) table.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 16.31% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-189 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-08-05 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| adobe | acrobat |
| adobe | acrobat reader |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Acrobat Acrobat - Font Parsing Integer Overflow | 2010-08-14 |
References
- http://secunia.com/advisories/40766
- http://securityevaluators.com/files/papers/CrashAnalysis.pdf
- http://www.us-cert.gov/cas/techalerts/TA10-231A.html
- http://www.zdnet.co.uk/news/security-threats/2010/08/04/adobe-confirms-pdf-security-hole-in-reader-40089737/
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11693
- http://secunia.com/advisories/40766
- http://securityevaluators.com/files/papers/CrashAnalysis.pdf
- http://www.us-cert.gov/cas/techalerts/TA10-231A.html
- http://www.zdnet.co.uk/news/security-threats/2010/08/04/adobe-confirms-pdf-security-hole-in-reader-40089737/
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11693
→ the Explorer · watch your stack · NVD