CVE-2009-4324
KEVHIGH 9.3EPSS 81.9%
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 81.93% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-06-08
- Published
- 2009-12-15
- Updated
- 2025-10-22
Proof-of-concept exploits (1)
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/16623
- https://www.exploit-db.com/exploits/16503
- https://www.exploit-db.com/exploits/10618