Summary
A crafted PDF can trigger a use-after-free flaw in Adobe Reader and Acrobat's media.newPlayer JavaScript path. The attacker needs a victim to open the malicious document so the embedded JavaScript runs and reuses freed memory in a controlled way. Successful exploitation can lead to arbitrary code execution in the user's security context.
Why Planned Fix?
4/6Exploitation Details
Execute arbitrary code as the logged-in user
RCE (Remote Code Execution)Affected Software
| Product | Affected Versions |
|---|---|
| Adobe Reader | 9.x before 9.3, 8.x before 8.2 |
| Adobe Acrobat | 9.x before 9.3, 8.x before 8.2 |
Desktop software for viewing, creating, annotating, and editing PDF documents.
Affected ComponentPDF JavaScript media.newPlayer method in Multimedia.api
PDF JavaScript media.newPlayer method in Multimedia.api
Disable Acrobat/Reader JavaScript or use Adobe's JavaScript Blacklist Framework; DEP reduced impact in some supported Windows configurations.
Disable Acrobat/Reader JavaScript or use Adobe's JavaScript Blacklist Framework; DEP reduced impact in some supported Windows configurations.
Not available
Upgrade Adobe Reader to 9.3 or later and Adobe Acrobat to 9.3 or later; Adobe's January 2010 update also provided 8.2 releases for the older branch.
Upgrade Adobe Reader to 9.3 or later and Adobe Acrobat to 9.3 or later; Adobe's January 2010 update also provided 8.2 releases for the older branch.
Probability of exploitation in the next 30 days
Worse than 100% of all CVEs
No known threat actors
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Affected Software (CPE) (7)
- •cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
- •cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
- •cpe:2.3:a:suse:linux_enterprise_debuginfo:11:-:*:*:*:*:*:*
- •cpe:2.3:o:opensuse:opensuse:11.1:*:*:*:*:*:*:*
- •cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*
- •cpe:2.3:o:suse:linux_enterprise:10.0:sp2:*:*:*:*:*:*
- •cpe:2.3:o:suse:linux_enterprise:10.0:sp3:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| nvd.nist.gov | CVE-2009-4324 Detail |
| www.adobe.com | Security Advisory for Adobe Reader and Acrobat |
| blog.adobe.com | Important: Acrobat 9.3 and Acrobat 8.2 Updates Available |
| blog.talosintelligence.com | Adobe Reader media.newPlayer() Analysis (CVE-2009-4324) |
| www.juniper.net | HTTP: Adobe Reader and Acrobat media.newPlayer Code Execution |
| www.tenable.com | CVE-2009-4324 Plugins |
| www.cisa.gov | Known Exploited Vulnerabilities Catalog |
| github.com | adobe_media_newplayer exploit module |
Priority History
Initial analysis