EXPOSURES › CVE-2009-1862
CVE-2009-1862
HIGH ⌖ ON CISA KEV · EXPLOITEDUnpatched Adobe Acrobat/Reader and Flash Player RCE vulnerabilities were actively exploited in the wild, enabling remote code execution.
Adobe Acrobat, Reader, and Flash Player contained unspecified remote code execution vulnerabilities that were actively exploited in the wild. DIB organizations must ensure these products are patched immediately, as unpatched RCE flaws allow attackers to execute arbitrary code on systems, leading to data breaches and compliance violations. The high embarrassment score reflects Adobe's repeated history of critical RCE vulnerabilities in widely deployed products.
Shame score — Adobe's repeated critical RCE vulnerabilities in widely deployed products, combined with active exploitation in the wild, demonstrate a pattern of avoidable security failures that severely impact DIB compliance and trust.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS).
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |