LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2009-1862: Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 8, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 22, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2009-1862 to its Known Exploited Vulnerabilities catalog on Jun 8, 2022, with a federal patch deadline of Jun 22, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS).

CVE-2009-1862 is an unspecified vulnerability in Adobe Acrobat and Reader and Adobe Flash Player that can let remote attackers execute code or cause a denial-of-service condition. It matters because these products have historically been common on endpoints that open documents and web content, giving an attacker a path to run code in the context of the user or disrupt availability if the software is still present and unpatched.

CISA notes that Adobe Acrobat and Reader should be updated per vendor instructions, while Adobe Flash Player is end-of-life and should be disconnected if still in use. Confirm all version and configuration details against the vendor advisory before acting.

How it works

The weakness is classified as CWE-94, which covers improper control of code generation (code injection). In products of this class, flawed handling of untrusted input can allow an attacker to introduce or influence code that the application then executes.

According to the CISA summary, Adobe Acrobat and Reader and Adobe Flash Player allow remote attackers to execute code or cause denial-of-service. An attacker would typically deliver crafted content—such as a malicious document or Flash-related payload—that the vulnerable component processes. Successful abuse can lead to arbitrary code running with the privileges of the affected application or to a crash that denies service. Exact exploit mechanics are not detailed in the provided facts; treat any public proof-of-concept claims cautiously and verify behavior only against official vendor guidance.

Am I affected? How to find it in your systems

Adobe Acrobat and Reader commonly appear on workstations and servers used for PDF viewing and creation. Adobe Flash Player historically ran in browsers and standalone players; it is now end-of-life and should not remain installed.

How to remediate

Patch first. For Adobe Acrobat and Reader, apply the updates specified by the vendor for this CVE. Follow the vendor’s installation and verification steps exactly, then confirm the new version is present across the estate.

For Adobe Flash Player, the product is end-of-life. Disconnect and remove it wherever it is still found; do not attempt to keep it running under the assumption that a patch exists.

If you can't patch immediately

Reduce exposure until updates or removal can be completed.

If your data may have been exposed

Actively exploited vulnerabilities can lead to unauthorized access or further compromise even when ransomware use is not documented for this CVE. If you suspect exploitation, isolate affected hosts, preserve forensic evidence, and follow your incident-response process. As a further check, you can run a free exposure scan of your email addresses against known breach data to see whether credentials or personal information have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · Acrobat and Reader, Flash Player
WeaknessCWE-94
Added to CISA KEVJun 8, 2022
Federal patch deadlineJun 22, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities