LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2010-0188: Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2010-0188 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code.

CVE-2010-0188 is an unspecified vulnerability in Adobe Reader and Acrobat that can allow an attacker to cause a denial of service or possibly execute arbitrary code. It is tracked as a code-injection weakness (CWE-94). Public detail on exact mechanics is limited; defenders should treat it as a serious client-side risk on systems that open untrusted PDF content. CISA notes known ransomware use, so timely remediation matters for environments still running these products.

IT and security teams should confirm affected builds, patch status, and exposure against the vendor advisory rather than relying on secondary summaries. The required action is to apply updates per vendor instructions.

How it works

CWE-94 covers improper control of code generation, often called code injection. In products like Adobe Reader and Acrobat, this class of flaw typically arises when the application processes crafted input (such as a malicious PDF) in a way that lets attacker-controlled data influence executable behavior. The CISA summary states the issue allows denial of service or possibly arbitrary code execution; further exploit specifics are not provided in the given record and must not be assumed.

An attacker would generally need to deliver a malicious file or content that the vulnerable Reader or Acrobat component processes. Successful abuse could crash the application or, in worse cases, run code in the context of the user who opened the file. Because the vulnerability is described as unspecified beyond that outcome, treat any untrusted PDF workflow as a potential delivery path and validate technical details only against Adobe’s advisory.

Am I affected? How to find it in your systems

Adobe Reader and Acrobat commonly run on end-user workstations and some shared or VDI desktops where staff view or sign PDFs. Inventory every host that has these products installed, including older or side-by-side deployments that users may still launch by default.

How to remediate

Patch first. Apply the updates Adobe released for this issue exactly as described in the vendor advisory and in line with CISA’s required action: apply updates per vendor instructions. After deployment, verify the installed build matches a fixed version and that the old binaries are no longer in use.

If you can't patch immediately

When immediate patching is blocked, apply compensating controls that shrink the attack surface until the vendor update can be installed.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, can lead to endpoint compromise and follow-on data theft or encryption. If you have evidence that vulnerable Adobe Reader or Acrobat instances processed untrusted content or showed signs of abuse, follow your incident-response process: isolate hosts, preserve forensic data, credential-reset where appropriate, and assess lateral movement. You can also run a free exposure scan of your email addresses against known breach datasets to see whether associated credentials or personal data already appear in public breach corpora, then prioritize password changes and monitoring accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · Reader and Acrobat
WeaknessCWE-94
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities