← All CVEs

CVE-2009-1862

high · 7.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

For Adobe Acrobat and Reader, apply updates per vendor instructions. For Adobe Flash Player, the impacted product is end-of-life and should be disconnected if still in use.

Added 2022-06-08Remediation due 2022-06-22

Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.

7.8
CVSS
24.9%
EPSS (exploit prob.)
98th
EPSS percentile
2009-07-23
Published

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-787

Affected products

VendorProductAffected versions
adobeacrobat>= 9.0, <= 9.1.2
adobeacrobat_reader>= 9.0, <= 9.1.2
adobeflash_player>= 9.0, <= 9.0.159.0
adobeflash_player>= 10.0, <= 10.0.22.87

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-1862