Junglewise Threat Intelligence

CVE-2009-4324: Adobe Acrobat and Reader Use-After-Free Vulnerability

CVE-2009-4324 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2022-06-08

Technologies: Adobe Acrobat, Adobe Reader, Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

A use-after-free vulnerability exists in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat. Remote attackers can execute arbitrary code via a crafted PDF file utilizing ZLib compressed streams.

Affected products

  • Adobe Acrobat 9.x before 9.3, 8.x before 8.2
  • Adobe Reader 9.x before 9.3, 8.x before 8.2

Timeline

  • 2009-12: exploited: Exploited in the wild in December 2009.
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats