CVE-2007-5020Code Injection in Adobe Acrobat

CWE-94Code Injection5 documents5 sources
Severity
9.3CRITICALNVD
EPSS
30.9%
top 3.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 21
Latest updateMay 1

Description

Unspecified vulnerability in Adobe Acrobat and Reader 8.1 on Windows allows remote attackers to execute arbitrary code via a crafted PDF file, related to the mailto: option and Internet Explorer 7 on Windows XP. NOTE: this information is based upon a vague pre-advisory by a reliable researcher.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-8vgw-qr5q-9wv4: Unspecified vulnerability in Adobe Acrobat and Reader 82022-05-01
VulnCheck
Adobe Acrobat and Reader Improper Control of Generation of Code ('Code Injection')2007

📋Vendor Advisories

1
Red Hat
CVE-2007-5020: Unspecified vulnerability in Adobe Acrobat and Reader 8

💬Community

1
Bugzilla
CVE-2007-1199 acroread arbitrary file:// URL execution2007-03-05
CVE-2007-5020 — Code Injection in Adobe Acrobat | cvebase