CVE-2010-0188 is an unspecified vulnerability impacting Adobe Reader and Acrobat versions 8.x before 8.2.1 and 9.x before 9.3.1. This flaw can lead to a denial of service (application crash) or potentially arbitrary code execution through unknown vectors. With a CVSS score of 7.8 (HIGH), it presents a significant risk due to its high impact on confidentiality, integrity, and availability, and its low attack complexity. This vulnerability is actively exploited, listed in CISA's KEV catalog, and has multiple Metasploit modules available, indicating widespread exploitability. Its high EPSS score, numerous community discussions, and extensive media coverage further highlight its critical nature and continued relevance to threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0, < 8.2.1CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 9.0, < 9.3.1CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 8.0, < 8.2.1CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* | ||
>= 9.0, < 9.3.1CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.