CVE-2009-1862

HIGH(7.8)KEVElevated Risk

Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability

Description

CVE-2009-1862 is an unspecified vulnerability affecting both Adobe Acrobat/Reader and Adobe Flash Player that allows remote attackers to execute arbitrary code or cause a denial of service. The flaw can be exploited through malicious Flash content served via web pages or through SWF content embedded in PDF documents, providing attackers with multiple exploitation vectors. CISA has added CVE-2009-1862 to its Known Exploited Vulnerabilities catalog, confirming active exploitation. With an EPSS score of 58.6% (98th percentile), this vulnerability has a significant probability of active exploitation.

KEV Information

Vendor
Adobe
Product
Acrobat and Reader, Flash Player
Date Added
June 8, 2022
Due Date
June 22, 2022
Required Action
For Adobe Acrobat and Reader, apply updates per vendor instructions. For Adobe Flash Player, the impacted product is end-of-life and should be disconnected if still in use.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
adobeacrobat>= 9.0, <= 9.1.2
adobeacrobat reader>= 9.0, <= 9.1.2
adobeflash player>= 9.0, <= 9.0.159.0; >= 10.0, <= 10.0.22.87

Multiple CVSS Assessments

Source: [email protected](Primary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

CVE-2009-1862 is associated with improper memory handling in both Adobe Flash Player and the Flash rendering components of Adobe Acrobat and Reader. Though the specific mechanism was not fully disclosed, the vulnerability allows crafted content to corrupt memory beyond intended buffer boundaries, enabling arbitrary code execution or denial of service.

Learn more: CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer

Impact Analysis

CVE-2009-1862 is remotely exploitable through two distinct attack vectors: malicious web pages containing Flash content, and PDF documents with embedded SWF objects. No authentication is required, and user interaction is limited to visiting a page or opening a document. Successful exploitation enables arbitrary code execution with the privileges of the affected application, placing confidentiality, integrity, and availability at full risk. The dual-product nature of this vulnerability — affecting both Flash Player and Adobe Reader — significantly expands the attack surface. The EPSS score of 58.6% (98th percentile) indicates a high probability of exploitation, and Flash Player's end-of-life status means one attack vector will never be patched.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2009-1862 in the wild by adding it to the Known Exploited Vulnerabilities catalog on June 8, 2022. The EPSS score of 58.6% places this vulnerability in the 98th percentile, indicating significant exploitation activity. CVE-2009-1862 was exploited as a zero-day vulnerability affecting both Adobe Flash Player and Adobe Acrobat/Reader simultaneously, demonstrating its versatility as an attack vector. The CISA required action differentiates between the two products: for Adobe Acrobat and Reader, apply updates per vendor instructions; for Adobe Flash Player, the product is end-of-life and should be disconnected. No specific ransomware association has been reported.

Remediation

  1. Remove Adobe Flash Player entirely: Flash Player is end-of-life and should be completely uninstalled from all systems, as the Flash Player attack vector will never receive a patch.
  2. Apply Adobe security updates for Acrobat and Reader: Install the latest patches for Adobe Acrobat and Reader to address the vulnerability in the SWF rendering component within PDF documents.
  3. Disable Flash content rendering in PDF readers: Configure Adobe Reader to block the execution of embedded Flash (SWF) content within PDF documents, eliminating the PDF-based attack vector.
  4. Block Flash content at all network entry points: Configure email gateways, web proxies, and firewalls to block SWF files, both standalone and embedded within PDF documents or other containers.
  5. Monitor for multi-vector exploitation attempts: Deploy endpoint detection capabilities that monitor for both web-based Flash exploitation and PDF-embedded Flash attacks, as this vulnerability can be delivered through either vector.

Technical Details

CVE-2009-1862 is a vulnerability that uniquely affects both Adobe Flash Player and the Flash rendering component within Adobe Acrobat and Reader. The specific technical details were not fully disclosed by Adobe, but the vulnerability is associated with improper memory handling (CWE-119) during Flash content processing. The dual-product nature of this vulnerability means it can be triggered through two distinct paths: directly via malicious SWF content in a web page rendered by Flash Player, or indirectly via SWF content embedded within a PDF document rendered by Adobe Reader's built-in Flash interpreter. This dual attack surface made the vulnerability particularly valuable, as attackers could choose between web-based delivery for mass exploitation or PDF-based delivery for targeted spear-phishing campaigns, depending on their objectives.

Frequently Asked Questions

Is CVE-2009-1862 being actively exploited?

Yes. CISA has confirmed active exploitation by adding CVE-2009-1862 to the Known Exploited Vulnerabilities catalog. The EPSS score of 58.6% in the 98th percentile indicates significant exploitation activity. The vulnerability was used in zero-day attacks targeting both Flash Player and Adobe Reader.

What products are affected by CVE-2009-1862?

CVE-2009-1862 affects both Adobe Acrobat/Reader and Adobe Flash Player. The Flash Player component has reached end-of-life, while Adobe Acrobat and Reader require patching to the latest supported version.

How do I fix CVE-2009-1862?

Remove Adobe Flash Player entirely (end-of-life). For Adobe Acrobat and Reader, apply the latest security updates and disable Flash content rendering within PDF documents.

How severe is CVE-2009-1862?

CVE-2009-1862 is a severe vulnerability affecting two Adobe products simultaneously, with an EPSS score in the 98th percentile. The dual attack surface through both web-based Flash content and PDF-embedded Flash makes this vulnerability exceptionally versatile for attackers.

CVSS Score

7.8
HIGH(7.8)

EPSS Score

EPSS Score25.01%
EPSS Percentile97.7%

Dates

PublishedJuly 23, 2009
Last ModifiedJune 16, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.