CVE-2009-4324 is a critical use-after-free vulnerability in the Doc.media.newPlayer method within Adobe Reader and Acrobat versions 9.x prior to 9.3 and 8.x prior to 8.2 on Windows and Mac OS X. This flaw allows remote attackers to execute arbitrary code by tricking users into opening a specially crafted PDF file utilizing ZLib compressed streams. With a CVSS score of 7.8 (High), this vulnerability is easily exploitable via user interaction (opening a malicious PDF) and can lead to complete compromise of confidentiality, integrity, and availability. It has been actively exploited in the wild since December 2009, with multiple Metasploit modules and ExploitDB entries available, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0, < 8.2CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 9.0, < 9.3CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 8.0, < 8.2CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* | ||
>= 9.0, < 9.3CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:a:suse:linux_enterprise_debuginfo:11:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.