CVE-2009-4764
published 2010-04-05CVE-2009-4764: Adobe Reader 8.x and 9.x on Windows is able to execute EXE files that are embedded in a PDF document, which makes it easier for remote attackers to trick users…
PriorityP342critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.55%
88.1th percentile
Adobe Reader 8.x and 9.x on Windows is able to execute EXE files that are embedded in a PDF document, which makes it easier for remote attackers to trick users into executing arbitrary code via a crafted document.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Acrobat Reader 9.0 code injection (XFDB-57994 / ID 801545)
vuldb·2026-05-05·CVSS 9.3
CVE-2009-4764 [CRITICAL] Adobe Acrobat Reader 9.0 code injection (XFDB-57994 / ID 801545)
A vulnerability has been found in Adobe Acrobat Reader 9.0 and classified as critical. This issue affects some unknown processing. This manipulation causes code injection.
This vulnerability appears as CVE-2009-4764. The attack may be initiated remotely. In addition, an exploit is available.
GHSA
GHSA-9297-53fw-x6cq: Adobe Reader 8
ghsa_unreviewed·2022-05-02
CVE-2009-4764 [HIGH] CWE-94 GHSA-9297-53fw-x6cq: Adobe Reader 8
Adobe Reader 8.x and 9.x on Windows is able to execute EXE files that are embedded in a PDF document, which makes it easier for remote attackers to trick users into executing arbitrary code via a crafted document.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.immunitysec.com/pipermail/dailydave/2010-April/006072.htmlhttp://lists.immunitysec.com/pipermail/dailydave/2010-April/006074.htmlhttp://www.metasploit.com/redmine/projects/framework/repository/revisions/8379/changes/modules/exploits/windows/fileformat/adobe_pdf_embedded_exe.rbhttps://exchange.xforce.ibmcloud.com/vulnerabilities/57994https://forum.immunityinc.com/board/thread/1199/exploiting-pdf-files-without-vulnerabili/?page=1#post-1199https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6976http://lists.immunitysec.com/pipermail/dailydave/2010-April/006072.htmlhttp://lists.immunitysec.com/pipermail/dailydave/2010-April/006074.htmlhttp://www.metasploit.com/redmine/projects/framework/repository/revisions/8379/changes/modules/exploits/windows/fileformat/adobe_pdf_embedded_exe.rbhttps://exchange.xforce.ibmcloud.com/vulnerabilities/57994https://forum.immunityinc.com/board/thread/1199/exploiting-pdf-files-without-vulnerabili/?page=1#post-1199https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6976
2010-04-05
Published