Executive brief
A stack-based buffer overflow in Adobe Reader and Acrobat allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab object. This vulnerability stems from improper input validation in a JavaScript method.
Affected products
- Adobe Reader 9 before 9.1, 8 before 8.1.3, and 7 before 7.1.1
- Adobe Acrobat 9 before 9.1, 8 before 8.1.3, and 7 before 7.1.1
Timeline
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-25: disclosed
- 2009-03-25: exploited: Reported as exploited in the wild in 2009 per historical context and CISA KEV status.