CVE-2009-4324
Summary
| CVE | CVE-2009-4324 |
|---|---|
| State | PUBLISHED |
| Assigner | adobe |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-12-15 02:30:00 UTC |
| Updated | 2026-04-21 21:12:37 UTC |
| Description | Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.818060000 probability, percentile 0.996120000 (date 2026-07-22)
CISA KEV: Listed on 2022-06-08; due 2022-06-22; ransomware use Unknown
Problem Types: CWE-416 | n/a | CWE-416 CWE-416 Use After Free
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | ADP | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
CISA Known Exploited Vulnerability
| Vendor | Adobe |
|---|---|
| Product | Acrobat and Reader |
| Name | Adobe Acrobat and Reader Use-After-Free Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2009-4324 |
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link |
| Red Hat update for acroread - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link, Vendor Advisory |
| Adobe Reader/Acrobat Memory Corruption Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| Zero-Day Xmas Present | Symantec Connect | af854a3a-2127-422b-91ae-364da2661108 | www.symantec.com | Broken Link |
| Metasploit Framework - /modules/exploits/windows/fileformat/adobe_media_newplayer.rb - Metasploit Redmine Interface | af854a3a-2127-422b-91ae-364da2661108 | www.metasploit.com | Broken Link |
| US-CERT Vulnerability Note VU#508357 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| Adobe - Security Bulletin APSB10-02 Security updates available for Adobe Reader and Acrobat | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Not Applicable |
| 547799 – (CVE-2009-4324) CVE-2009-4324 acroread: media.newplayer JavaScript API code execution vulnerability (APSB10-02) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link |
| Adobe Reader and Acrobat 'newplayer()' JavaScript Method Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| contagio: Dec.11 Adobe 0 day CVE-2009-4324 Attack of the Day (#1). Fwd: Reference from [email protected] Fri 2009-12-11 01:08 | af854a3a-2127-422b-91ae-364da2661108 | contagiodump.blogspot.com | Exploit, Third Party Advisory |
| Adobe Reader/Acrobat 7 Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| Adobe - Security Advisories: APSA09-07 - Security Advisory for Adobe Reader and Acrobat | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Vendor Advisory |
| [security-announce] SUSE Security Announcement: acoread (SUSE-SA:2010:00 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List, Third Party Advisory |
| osvdb.org/60980 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| New Adobe Reader and Acrobat Vulnerability - Adobe Product Security Incident Response Team (PSIRT) | af854a3a-2127-422b-91ae-364da2661108 | blogs.adobe.com | Broken Link, Vendor Advisory |
| Shadowserver Foundation - Calendar - 2009-12-14 | af854a3a-2127-422b-91ae-364da2661108 | www.shadowserver.org | Broken Link |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link |
| US-CERT Technical Cyber Security Alert TA10-013A -- Adobe Reader and Acrobat Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2022-06-08T00:00:00.000Z | CVE-2009-4324 added to CISA KEV |
There are currently no legacy QID mappings associated with this CVE.