Vulnerability record · CVE-2007-0045 · published 3 January 2007
CVE-2007-0045: Adobe Acrobat Reader Plugin Universal XSS via PDF URL parameters
Adobe · Acrobat
The Adobe Acrobat Reader browser plugin before 8.0.0 (and possibly versions shipped with Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2) fails to properly handle javascript: and res: URIs supplied through .pdf URLs, FDF/XML/XFDF AJAX parameters, or arbitrarily named anchor identifiers. This lets a remote attacker inject arbitrary JavaScript into the context of the victim's browser, a flaw publicly named "Universal XSS (UXSS)." Because the plugin is invoked by the browser, the issue crosses site boundaries and undermines the same-origin protections users rely on.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw is remotely reachable and has public exploit material with very high EPSS, but it requires user interaction, is not in KEV, and affects legacy plugin versions that are largely retired.
What it is
The Adobe Acrobat Reader browser plugin before 8.0.0 (and possibly versions shipped with Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2) fails to properly handle javascript: and res: URIs supplied through .pdf URLs, FDF/XML/XFDF AJAX parameters, or arbitrarily named anchor identifiers. This lets a remote attacker inject arbitrary JavaScript into the context of the victim's browser, a flaw publicly named "Universal XSS (UXSS)." Because the plugin is invoked by the browser, the issue crosses site boundaries and undermines the same-origin protections users rely on.
Impact
An attacker can execute arbitrary JavaScript in the victim's browser session, enabling cookie theft, session hijacking, page content manipulation, and other script-driven attacks against any site the victim visits. The CVSS 2.0 vector (AV:N/AC:M/Au:N/C:N/I:P/A:N) rates only partial integrity impact, so the score understates the cross-site reach of the flaw.
Attack surface
Reached remotely over the network by luring a user to a crafted .pdf URL or page that passes malicious FDF, XML, XFDF, or anchor parameters to the Acrobat Reader plugin; no authentication is required, but user interaction (opening the link or page) is needed. The vector is AV:N/AC:M/Au:N, consistent with a medium-complexity, unauthenticated, user-driven attack.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is 0.46592 (98.8th percentile) and multiple references are tagged Exploit, indicating public exploit material exists. The record does not state whether exploitation is observed in the wild.
What to do
- Upgrade the Adobe Acrobat Reader plugin to 8.0.0 or later, and apply the later fixes referenced for Reader 7.1.4, 8.1.7, and 9.2 as applicable.
- Disable or remove the Acrobat Reader browser plugin where PDF viewing in the browser is not required, or configure the browser to open PDFs in the standalone reader.
- Apply vendor and distribution patches (Adobe APSB07-01, APSB09-15, and the SUSE, Gentoo, Slackware, and Sun advisories listed).
- Restrict users from following untrusted .pdf links and treat javascript: and res: URIs in PDF contexts as suspicious.
- Keep browsers and plugins current, since the flaw spans Firefox, Internet Explorer 6 SP1, Chrome, and Opera versions listed.
Detection
- Monitor browser and proxy logs for .pdf URLs containing javascript: or res: URIs, or FDF, XML, XFDF, and name= anchor parameters.
- Alert on Acrobat Reader plugin process activity spawned from browser sessions that then makes unexpected network requests.
- Hunt for known exploit URLs and payload patterns from the referenced public exploit write-ups in web and endpoint telemetry.
- Track endpoint inventory for Acrobat Reader plugin versions below 8.0.0 (and the affected 7.x, 8.x, 9.x builds) and flag them for remediation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-0045 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-0045), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.