CVE-2009-4764: Code Injection
Published Apr 5, 2010
·Updated
Adobe Reader 8.x and 9.x on Windows is able to execute EXE files that are embedded in a PDF document, which makes it easier for remote attackers to trick users into executing arbitrary code via a crafted document.
Affected Software
32 affected components
Adobe Acrobat reader=8.0
Adobe Acrobat reader=8.1
Adobe Acrobat reader=8.1.1
Adobe Acrobat reader=8.1.2
Adobe Acrobat reader=8.1.4
Adobe Acrobat reader=8.1.5
Adobe Acrobat reader=8.1.6
Adobe Acrobat reader=8.1.7
Adobe Acrobat reader=9.0
Adobe Acrobat reader=9.1
Adobe Acrobat reader=9.1.1
Adobe Acrobat reader=9.1.2
Adobe Acrobat reader=9.1.3
Adobe Acrobat reader=9.2
Adobe Acrobat reader=9.3
Microsoft Windows
All of the following
Any of the following
Adobe Acrobat reader=8.0
Adobe Acrobat reader=8.1
Adobe Acrobat reader=8.1.1
Adobe Acrobat reader=8.1.2
Adobe Acrobat reader=8.1.4
Adobe Acrobat reader=8.1.5
Adobe Acrobat reader=8.1.6
Adobe Acrobat reader=8.1.7
Adobe Acrobat reader=9.0
Adobe Acrobat reader=9.1
Adobe Acrobat reader=9.1.1
Adobe Acrobat reader=9.1.2
Adobe Acrobat reader=9.1.3
Adobe Acrobat reader=9.2
Adobe Acrobat reader=9.3
Microsoft Windows
Event History
Apr 5, 2010
CVE Published
via MITRE·03:15 PM
Data Sourced
via MITRE·03:15 PM
Description
Data Sourced
03:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·03:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4764?
CVE-2009-4764 has a severity rating of critical as it allows remote attackers to execute arbitrary code on affected systems.
2
How do I fix CVE-2009-4764?
To fix CVE-2009-4764, users should update Adobe Reader to the latest version that addresses this vulnerability.
3
Which versions of Adobe Reader are affected by CVE-2009-4764?
CVE-2009-4764 affects Adobe Reader versions 8.x and 9.x on Windows.
4
Can CVE-2009-4764 be exploited via social engineering?
Yes, CVE-2009-4764 can be exploited through social engineering by tricking users into opening a malicious PDF document.
5
What impact does CVE-2009-4764 have on users?
CVE-2009-4764 allows attackers to execute arbitrary code, potentially compromising the user's system and data.