PoC Index

CVE-2009-4324

KEVHIGH 9.3EPSS 81.9%

Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.

CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
81.93% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2022-06-08
Published
2009-12-15
Updated
2025-10-22

Proof-of-concept exploits (1)

Metasploit modules (1)

ExploitDB entries (3)

References

Related