Aller au contenu
Appaloosa Scout
HIGH 7.8 KEV

CVE-2009-4324

Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.

CVSS v3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA Known Exploited Vulnerability

Ajouté au KEV
2022-06-08
Deadline remédiation
2022-06-22
Action requise
Apply updates per vendor instructions.
Ransomware
Non

Apps mobiles affectées

Configurations CPE vulnérables

Vendor Produit Plateforme Versions CPE 2.3 URI
adobe acrobat_reader Android ≥8.0 <8.2 cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
adobe acrobat_reader iOS ≥8.0 <8.2 cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
adobe acrobat_reader Android ≥9.0 <9.3 cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
adobe acrobat_reader iOS ≥9.0 <9.3 cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
Voir sur NVD ↗ Catalogue CISA KEV ↗