⚠ Actively exploited
Added to CISA KEV on 2022-06-08. Federal agencies required to patch by 2022-06-22. Required action: For Adobe Acrobat and Reader, apply updates per vendor instructions. For Adobe Flash Player, the impacted product is end-of-life and should be disconnected if still in use..

CVE-2009-1862Out-of-bounds Write in Adobe Acrobat

Severity
7.8HIGHNVD
EPSS
58.6%
top 1.78%
CISA KEV
KEV
Added 2022-06-08
Due 2022-06-22
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJul 23
KEV addedJun 8
KEV dueJun 22
Latest updateMar 25
CISA Required Action: For Adobe Acrobat and Reader, apply updates per vendor instructions. For Adobe Flash Player, the impacted product is end-of-life and should be disconnected if still in use.

Description

Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDadobe/flash_player9.09.0.159.0+1
NVDadobe/acrobat_reader9.09.1.2
NVDadobe/acrobat9.09.1.2

🔴Vulnerability Details

2
GHSA
GHSA-wx6p-35hf-vhhj: Unspecified vulnerability in Adobe Reader and Acrobat 92022-05-02
VulnCheck
Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability2009

📋Vendor Advisories

3
Red Hat
kernel: btrfs: do not BUG_ON in link_to_fixup_dir2024-03-25
CISA
Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability2022-06-08
Red Hat
flash-plugin: Remote code execution vulnerability via malicious SWF (Shockwave Flash) content2009-07-21

🕵️Threat Intelligence

1
Zscaler
In The Wild Flash Exploit Analysis – Part 1 | Zscaler2009-09-10

💬Community

2
Bugzilla
flash-plugin: multiple code execution flaws (APSB09-10)2009-07-31
Bugzilla
CVE-2009-1862 acroread, flash-plugin: Remote code execution vulnerability via malicious SWF (Shockwave Flash) content2009-07-23
CVE-2009-1862 — Out-of-bounds Write in Adobe Acrobat | cvebase