CVE-2010-1240 is a critical vulnerability in Adobe Reader and Acrobat versions 8.x and 9.x on Windows and Mac OS X. It allows attackers to manipulate the "Launch File" warning dialog, tricking users into executing arbitrary local programs embedded within a PDF document. This vulnerability has a CVSS score of 9.3, indicating a severe risk with network-based attacks, medium complexity, and complete compromise of confidentiality, integrity, and availability. While not on the KEV catalog, exploit modules are readily available in Metasploit and ExploitDB, demonstrating its exploitability. Despite its age and high EPSS score, there is no significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.3.1CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:9.3.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.