Skip to content
COOEY

EXPOSURES › CVE-2009-1862

CVE-2009-1862

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-06-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2009-1862 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Unpatched Adobe Acrobat/Reader and Flash Player RCE vulnerabilities were actively exploited in the wild, enabling remote code execution.

Adobe Acrobat, Reader, and Flash Player contained unspecified remote code execution vulnerabilities that were actively exploited in the wild. DIB organizations must ensure these products are patched immediately, as unpatched RCE flaws allow attackers to execute arbitrary code on systems, leading to data breaches and compliance violations. The high embarrassment score reflects Adobe's repeated history of critical RCE vulnerabilities in widely deployed products.

Shame score — Adobe's repeated critical RCE vulnerabilities in widely deployed products, combined with active exploitation in the wild, demonstrate a pattern of avoidable security failures that severely impact DIB compliance and trust.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS).

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized