CVE-2009-1862: Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability
Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS).
Other sources
Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Disconnect Adobe Flash Player (versions 9.x through 9.0.159.0 and 10.x through 10.0.22.87) if still in use — isolate hosts running these versions or block Adobe Flash Player traffic at the network boundary/firewall, since the product is end-of-life.
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1862?
CVE-2009-1862 has been classified as a critical vulnerability due to its potential to allow remote code execution and denial-of-service attacks.
How do I fix CVE-2009-1862?
To fix CVE-2009-1862, users should update Adobe Acrobat, Reader, and Flash Player to the latest versions that have addressed this vulnerability.
Which versions of Adobe products are affected by CVE-2009-1862?
CVE-2009-1862 affects Adobe Acrobat and Reader versions 9.x through 9.1.2 and Adobe Flash Player versions 9.x through 9.0.159.0 and 10.x through 10.0.22.87.
What types of attacks can exploit CVE-2009-1862?
CVE-2009-1862 can be exploited by remote attackers to execute arbitrary code or cause a denial of service on affected systems.
Is CVE-2009-1862 still a risk today?
While CVE-2009-1862 was disclosed in 2009, systems running outdated versions of affected Adobe software remain at risk if they have not been updated.