Executive brief
A use-after-free vulnerability exists in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat. Remote attackers can execute arbitrary code via a crafted PDF file utilizing ZLib compressed streams.
Affected products
- Adobe Acrobat 9.x before 9.3, 8.x before 8.2
- Adobe Reader 9.x before 9.3, 8.x before 8.2
Timeline
- 2009-12: exploited: Exploited in the wild in December 2009.
- 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.