Junglewise Threat Intelligence

CVE-2010-2883: Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability

CVE-2010-2883 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2022-06-08

Technologies: Adobe Acrobat, Adobe Reader, Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

A stack-based buffer overflow vulnerability exists in the CoolType.dll component of Adobe Reader and Acrobat. The flaw is triggered by parsing a PDF document containing a specially crafted long field in a Smart INdependent Glyphlets (SING) table within a TrueType Font (TTF), allowing for remote code execution or denial of service.

Affected products

  • Adobe Reader 9.x before 9.4, 8.x before 8.2.5, 9.3.4 and earlier
  • Adobe Acrobat 9.x before 9.4, 8.x before 8.2.5, 9.3.4 and earlier

Timeline

  • 2010-09: exploited: Exploited in the wild.
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats