Junglewise Threat Intelligence

CVE-2009-1862: Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability

CVE-2009-1862 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2022-06-08

Technologies: Adobe Acrobat, Adobe Reader, Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

An unspecified memory corruption vulnerability in authplay.dll allows remote attackers to execute arbitrary code or cause a denial of service via a crafted Flash application in a PDF file or a standalone .swf file. This vulnerability was actively exploited in the wild starting in July 2009.

Affected products

  • Adobe Reader 9.x through 9.1.2
  • Adobe Acrobat 9.x through 9.1.2
  • Adobe Flash Player 9.x through 9.0.159.0, 10.x through 10.0.22.87

Timeline

  • 2009-07-21: exploited: Exploited in the wild in July 2009 according to NVD and Adobe PSIRT blog.
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats