EXPOSURES › CVE-2010-0188
CVE-2010-0188
CRITICAL ⌖ ON CISA KEV · EXPLOITEDA critical Adobe Reader/Acrobat vulnerability (CVE-2010-0188) allowed arbitrary code execution and is actively exploited, often linked to ransomware attacks.
This vulnerability in Adobe Reader/Acrobat enabled attackers to execute arbitrary code, potentially leading to system compromise and data exfiltration. DIB organizations using these products must ensure patching and consider compensating controls due to Adobe's history of similar vulnerabilities. Failure to address this could result in non-compliance with CMMC and NIST 800-171.
Shame score — Adobe's repeated history of critical RCE vulnerabilities in widely-used products demonstrates a pattern of negligence and insufficient security practices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |