CVE-2009-1862 is an unspecified vulnerability affecting Adobe Reader, Acrobat (versions 9.x through 9.1.2), and Flash Player (versions 9.x through 9.0.159.0 and 10.x through 10.0.22.87). This flaw allows remote attackers to execute arbitrary code or cause a denial of service through memory corruption, typically via crafted Flash applications embedded in PDF files or standalone SWF files, specifically related to authplay.dll. With a CVSS score of 7.8 (HIGH), the vulnerability requires user interaction (UI:R) but has low attack complexity (AC:L), potentially leading to high impact on confidentiality, integrity, and availability. This CVE is noteworthy for being actively exploited in the wild in July 2009 and is listed in CISA's KEV catalog, indicating its historical significance despite a lack of public exploit code or recent media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0, <= 9.1.2CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 9.0, <= 9.1.2CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* | ||
>= 9.0, <= 9.0.159.0CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 10.0, <= 10.0.22.87CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.