{"api_version":"1","generated_at":"2026-07-23T14:35:04+00:00","cve":"CVE-2009-4324","urls":{"html":"https://cve.report/CVE-2009-4324","api":"https://cve.report/api/cve/CVE-2009-4324.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-4324","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-4324"},"summary":{"title":"CVE-2009-4324","description":"Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.","state":"PUBLISHED","assigner":"adobe","published_at":"2009-12-15 02:30:00","updated_at":"2026-04-21 21:12:37"},"problem_types":["CWE-416","n/a","CWE-416 CWE-416 Use After Free"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"ADP","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54747","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54747","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/0103","name":"http://www.vupen.com/english/advisories/2010/0103","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/38215","name":"http://secunia.com/advisories/38215","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Red Hat update for acroread - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-4324","name":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-4324","refsource":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2009/3518","name":"http://www.vupen.com/english/advisories/2009/3518","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/37690","name":"http://secunia.com/advisories/37690","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Adobe Reader/Acrobat Memory Corruption Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.symantec.com/connect/blogs/zero-day-xmas-present","name":"http://www.symantec.com/connect/blogs/zero-day-xmas-present","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Zero-Day Xmas Present | Symantec Connect","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.metasploit.com/redmine/projects/framework/repository/revisions/7881/entry/modules/exploits/windows/fileformat/adobe_media_newplayer.rb","name":"http://www.metasploit.com/redmine/projects/framework/repository/revisions/7881/entry/modules/exploits/windows/fileformat/adobe_media_newplayer.rb","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Metasploit Framework - /modules/exploits/windows/fileformat/adobe_media_newplayer.rb - Metasploit Redmine Interface","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/508357","name":"http://www.kb.cert.org/vuls/id/508357","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"US-CERT Vulnerability Note VU#508357","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.adobe.com/support/security/bulletins/apsb10-02.html","name":"http://www.adobe.com/support/security/bulletins/apsb10-02.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"],"title":"Adobe - Security Bulletin APSB10-02 Security updates available for Adobe Reader and Acrobat","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=547799","name":"https://bugzilla.redhat.com/show_bug.cgi?id=547799","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"547799 – (CVE-2009-4324) CVE-2009-4324 acroread: media.newplayer JavaScript API code execution vulnerability (APSB10-02)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0060.html","name":"http://www.redhat.com/support/errata/RHSA-2010-0060.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/37331","name":"http://www.securityfocus.com/bid/37331","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"Adobe Reader and Acrobat 'newplayer()' JavaScript Method Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://contagiodump.blogspot.com/2009/12/virustotal-httpwww.html","name":"http://contagiodump.blogspot.com/2009/12/virustotal-httpwww.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"],"title":"contagio: Dec.11 Adobe 0 day  CVE-2009-4324 Attack of the Day (#1). Fwd: Reference from christanderson.ma@gmail.com Fri 2009-12-11 01:08","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/38138","name":"http://secunia.com/advisories/38138","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Adobe Reader/Acrobat 7 Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.adobe.com/support/security/advisories/apsa09-07.html","name":"http://www.adobe.com/support/security/advisories/apsa09-07.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Adobe - Security Advisories: APSA09-07 - Security Advisory for Adobe Reader and Acrobat","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html","name":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE Security Announcement: acoread (SUSE-SA:2010:00","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/60980","name":"http://osvdb.org/60980","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html","name":"http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"New Adobe Reader and Acrobat Vulnerability - Adobe Product Security Incident Response Team (PSIRT)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214","name":"http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Shadowserver Foundation - Calendar - 2009-12-14","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6795","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6795","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA10-013A.html","name":"http://www.us-cert.gov/cas/techalerts/TA10-013A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA10-013A -- Adobe Reader and Acrobat Vulnerabilities","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-4324","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-4324","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[{"source":"ADP","time":"2022-06-08T00:00:00.000Z","lang":"en","value":"CVE-2009-4324 added to CISA KEV"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"4324","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"acrobat","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2009","cve_id":"4324","cve":"CVE-2009-4324","vendorProject":"Adobe","product":"Acrobat and Reader","vulnerabilityName":"Adobe Acrobat and Reader Use-After-Free Vulnerability","dateAdded":"2022-06-08","shortDescription":"Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-06-22","knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2009-4324","cwes":"CWE-399","catalogVersion":"2026.07.22","updated_at":"2026-07-22 20:07:15"},"epss":{"cve_year":"2009","cve_id":"4324","cve":"CVE-2009-4324","epss":"0.818060000","percentile":"0.996120000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:33"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T07:01:20.249Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"37331","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/37331"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html"},{"name":"37690","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37690"},{"name":"38138","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38138"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=547799"},{"name":"60980","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/60980"},{"name":"VU#508357","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/508357"},{"name":"acro-reader-unspecifed-code-execution(54747)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54747"},{"name":"ADV-2009-3518","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/3518"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.metasploit.com/redmine/projects/framework/repository/revisions/7881/entry/modules/exploits/windows/fileformat/adobe_media_newplayer.rb"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/security/bulletins/apsb10-02.html"},{"name":"oval:org.mitre.oval:def:6795","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6795"},{"name":"RHSA-2010:0060","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0060.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://contagiodump.blogspot.com/2009/12/virustotal-httpwww.html"},{"name":"ADV-2010-0103","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0103"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/security/advisories/apsa09-07.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.symantec.com/connect/blogs/zero-day-xmas-present"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214"},{"name":"38215","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38215"},{"name":"SUSE-SA:2010:008","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html"},{"name":"TA10-013A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA10-013A.html"}],"title":"CVE Program Container"},{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}},{"other":{"content":{"id":"CVE-2009-4324","options":[{"Exploitation":"active"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2025-02-04T21:42:23.751240Z","version":"2.0.3"},"type":"ssvc"}},{"other":{"content":{"dateAdded":"2022-06-08","reference":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-4324"},"type":"kev"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-416","description":"CWE-416 Use After Free","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-10-22T00:05:53.934Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"references":[{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-4324"}],"timeline":[{"lang":"en","time":"2022-06-08T00:00:00.000Z","value":"CVE-2009-4324 added to CISA KEV"}],"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-12-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-18T12:57:01.000Z","orgId":"078d4453-3bcd-4900-85e6-15281da43538","shortName":"adobe"},"references":[{"name":"37331","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/37331"},{"tags":["x_refsource_MISC"],"url":"http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html"},{"name":"37690","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37690"},{"name":"38138","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38138"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=547799"},{"name":"60980","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/60980"},{"name":"VU#508357","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/508357"},{"name":"acro-reader-unspecifed-code-execution(54747)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54747"},{"name":"ADV-2009-3518","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/3518"},{"tags":["x_refsource_MISC"],"url":"http://www.metasploit.com/redmine/projects/framework/repository/revisions/7881/entry/modules/exploits/windows/fileformat/adobe_media_newplayer.rb"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/security/bulletins/apsb10-02.html"},{"name":"oval:org.mitre.oval:def:6795","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6795"},{"name":"RHSA-2010:0060","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0060.html"},{"tags":["x_refsource_MISC"],"url":"http://contagiodump.blogspot.com/2009/12/virustotal-httpwww.html"},{"name":"ADV-2010-0103","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0103"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/security/advisories/apsa09-07.html"},{"tags":["x_refsource_MISC"],"url":"http://www.symantec.com/connect/blogs/zero-day-xmas-present"},{"tags":["x_refsource_MISC"],"url":"http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214"},{"name":"38215","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38215"},{"name":"SUSE-SA:2010:008","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html"},{"name":"TA10-013A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA10-013A.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@adobe.com","ID":"CVE-2009-4324","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"37331","refsource":"BID","url":"http://www.securityfocus.com/bid/37331"},{"name":"http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html","refsource":"MISC","url":"http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html"},{"name":"37690","refsource":"SECUNIA","url":"http://secunia.com/advisories/37690"},{"name":"38138","refsource":"SECUNIA","url":"http://secunia.com/advisories/38138"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=547799","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=547799"},{"name":"60980","refsource":"OSVDB","url":"http://osvdb.org/60980"},{"name":"VU#508357","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/508357"},{"name":"acro-reader-unspecifed-code-execution(54747)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54747"},{"name":"ADV-2009-3518","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/3518"},{"name":"http://www.metasploit.com/redmine/projects/framework/repository/revisions/7881/entry/modules/exploits/windows/fileformat/adobe_media_newplayer.rb","refsource":"MISC","url":"http://www.metasploit.com/redmine/projects/framework/repository/revisions/7881/entry/modules/exploits/windows/fileformat/adobe_media_newplayer.rb"},{"name":"http://www.adobe.com/support/security/bulletins/apsb10-02.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/security/bulletins/apsb10-02.html"},{"name":"oval:org.mitre.oval:def:6795","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6795"},{"name":"RHSA-2010:0060","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2010-0060.html"},{"name":"http://contagiodump.blogspot.com/2009/12/virustotal-httpwww.html","refsource":"MISC","url":"http://contagiodump.blogspot.com/2009/12/virustotal-httpwww.html"},{"name":"ADV-2010-0103","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/0103"},{"name":"http://www.adobe.com/support/security/advisories/apsa09-07.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/security/advisories/apsa09-07.html"},{"name":"http://www.symantec.com/connect/blogs/zero-day-xmas-present","refsource":"MISC","url":"http://www.symantec.com/connect/blogs/zero-day-xmas-present"},{"name":"http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214","refsource":"MISC","url":"http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214"},{"name":"38215","refsource":"SECUNIA","url":"http://secunia.com/advisories/38215"},{"name":"SUSE-SA:2010:008","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html"},{"name":"TA10-013A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA10-013A.html"}]}}}},"cveMetadata":{"assignerOrgId":"078d4453-3bcd-4900-85e6-15281da43538","assignerShortName":"adobe","cveId":"CVE-2009-4324","datePublished":"2009-12-15T02:00:00.000Z","dateReserved":"2009-12-14T00:00:00.000Z","dateUpdated":"2025-10-22T00:05:53.934Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-12-15 02:30:00","lastModifiedDate":"2026-04-21 21:12:37","problem_types":["CWE-416","n/a","CWE-416 CWE-416 Use After Free"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*","versionStartIncluding":"8.0","versionEndExcluding":"8.2","matchCriteriaId":"9670133C-09FA-41F2-B0F7-BFE960E30B71"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0","versionEndExcluding":"9.3","matchCriteriaId":"EA95CC75-BF25-4BEB-B646-ACDBBE32AF4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*","versionStartIncluding":"8.0","versionEndExcluding":"8.2","matchCriteriaId":"3A8B3441-727A-4A78-A5A4-5A5011075510"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0","versionEndExcluding":"9.3","matchCriteriaId":"AADB6D5C-5448-4FF7-BB7B-3641EA56194E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*","matchCriteriaId":"4781BF1E-8A4E-4AFF-9540-23D523EE30DD"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:suse:linux_enterprise_debuginfo:11:-:*:*:*:*:*:*","matchCriteriaId":"C76D0C17-2AFF-4209-BBCD-36166DF7F974"},{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:11.1:*:*:*:*:*:*:*","matchCriteriaId":"FBF7B6A8-3DF9-46EC-A90E-6EF68C39F883"},{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*","matchCriteriaId":"A01C8B7E-EB19-40EA-B1D2-9AE5EA536C95"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise:10.0:sp2:*:*:*:*:*:*","matchCriteriaId":"6A3B50EE-F432-40BE-B422-698955A6058D"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise:10.0:sp3:*:*:*:*:*:*","matchCriteriaId":"1193A7E6-DCB4-4E79-A509-1D6948153A57"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"4324","Ordinal":"1","Title":"CVE-2009-4324","CVE":"CVE-2009-4324","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"4324","Ordinal":"1","NoteData":"Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.","Type":"Description","Title":"CVE-2009-4324"},{"CveYear":"2009","CveId":"4324","Ordinal":"2","NoteData":"2009-12-14","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"4324","Ordinal":"3","NoteData":"2017-09-18","Type":"Other","Title":"Modified"}]}}}