Back

HIGH KEV

acroread: media.newplayer JavaScript API code execution vulnerability (APSB10-02)

Published Dec 15, 2009 ·Due Jun 22, 2022

Description

Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (27)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Dec 15, 2009
Updated Oct 22, 2025
Reserved Dec 14, 2009
CISA Vulnrichment
Updated Feb 4, 2025
NVD
Status Analyzed
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Dec 14, 2009
ENISA EUVD
Assigner adobe
Published Dec 15, 2009
Updated Oct 22, 2025
Exploited since Jun 8, 2022
EUVD-2009-4292