CVE-2009-2169 describes an insecure method vulnerability in the Edraw PDF Viewer Component's ActiveX control (pdfviewer.ocx) prior to version 3.2.0.126. This critical vulnerability (CVSS 9.3) allows remote attackers to create and overwrite arbitrary files on a victim's system, potentially leading to code execution by writing to a Startup folder. While not actively exploited in the wild (KEV: No), public exploit code exists on ExploitDB, and the vulnerability has seen some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.2.0CPE matchmatch criteria | cpe:2.3:a:edraw:pdf_viewer_component:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.