CVE-2009-4324
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Adobe Acrobat and Reader Use-After-Free Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 82% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-416
מוצרים מושפעים
adobe: acrobat; adobe: acrobat reader; apple: mac os x; microsoft: windows; suse: linux enterprise debuginfo; opensuse: opensuse; suse: linux enterprise
קישורים
- http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html Broken LinkVendor Advisory
- http://secunia.com/advisories/37690 Broken LinkVendor Advisory
- http://secunia.com/advisories/38138 Broken LinkVendor Advisory
- http://secunia.com/advisories/38215 Broken LinkVendor Advisory
- http://www.adobe.com/support/security/advisories/apsa09-07.html Vendor Advisory
- http://www.vupen.com/english/advisories/2009/3518 Broken LinkVendor Advisory
- http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html Broken LinkVendor Advisory
- http://secunia.com/advisories/37690 Broken LinkVendor Advisory
- http://secunia.com/advisories/38138 Broken LinkVendor Advisory
- http://secunia.com/advisories/38215 Broken LinkVendor Advisory