CVE-2010-3625Code Injection in Adobe Acrobat

CWE-94Code Injection4 documents4 sources
Severity
9.3CRITICALNVD
EPSS
3.7%
top 11.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 6
Latest updateMay 14

Description

Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code via unspecified vectors, related to a "prefix protocol handler vulnerability."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDadobe/acrobat_reader24 versions+23
NVDadobe/acrobat25 versions+24

Patches

🔴Vulnerability Details

1
GHSA
GHSA-mc64-v3mw-vq6w: Adobe Reader and Acrobat 92022-05-14

📋Vendor Advisories

1
Red Hat
acroread: multiple code execution flaws (APSB10-21)2010-10-05

💬Community

1
Bugzilla
acroread: multiple code execution flaws (APSB10-21)2010-10-04
CVE-2010-3625 — Code Injection in Adobe Acrobat | cvebase