← Vulnerability feed

Vulnerability record · CVE-2007-0045 · published 3 January 2007

CVE-2007-0045: Adobe Acrobat Reader Plugin Universal XSS via PDF URL parameters

Adobe · Acrobat

The Adobe Acrobat Reader browser plugin before 8.0.0 (and possibly versions shipped with Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2) fails to properly handle javascript: and res: URIs supplied through .pdf URLs, FDF/XML/XFDF AJAX parameters, or arbitrarily named anchor identifiers. This lets a remote attacker inject arbitrary JavaScript into the context of the victim's browser, a flaw publicly named "Universal XSS (UXSS)." Because the plugin is invoked by the browser, the issue crosses site boundaries and undermines the same-origin protections users rely on.

4.3 CVSS 2.0 Medium EPSS 47% · top 1.2% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
88References, 10 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

medium priorityThe flaw is remotely reachable and has public exploit material with very high EPSS, but it requires user interaction, is not in KEV, and affects legacy plugin versions that are largely retired.

What it is

The Adobe Acrobat Reader browser plugin before 8.0.0 (and possibly versions shipped with Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2) fails to properly handle javascript: and res: URIs supplied through .pdf URLs, FDF/XML/XFDF AJAX parameters, or arbitrarily named anchor identifiers. This lets a remote attacker inject arbitrary JavaScript into the context of the victim's browser, a flaw publicly named "Universal XSS (UXSS)." Because the plugin is invoked by the browser, the issue crosses site boundaries and undermines the same-origin protections users rely on.

Impact

An attacker can execute arbitrary JavaScript in the victim's browser session, enabling cookie theft, session hijacking, page content manipulation, and other script-driven attacks against any site the victim visits. The CVSS 2.0 vector (AV:N/AC:M/Au:N/C:N/I:P/A:N) rates only partial integrity impact, so the score understates the cross-site reach of the flaw.

Attack surface

Reached remotely over the network by luring a user to a crafted .pdf URL or page that passes malicious FDF, XML, XFDF, or anchor parameters to the Acrobat Reader plugin; no authentication is required, but user interaction (opening the link or page) is needed. The vector is AV:N/AC:M/Au:N, consistent with a medium-complexity, unauthenticated, user-driven attack.

Exploitation

Not listed in CISA KEV and no ransomware association is documented, but EPSS is 0.46592 (98.8th percentile) and multiple references are tagged Exploit, indicating public exploit material exists. The record does not state whether exploitation is observed in the wild.

What to do

  • Upgrade the Adobe Acrobat Reader plugin to 8.0.0 or later, and apply the later fixes referenced for Reader 7.1.4, 8.1.7, and 9.2 as applicable.
  • Disable or remove the Acrobat Reader browser plugin where PDF viewing in the browser is not required, or configure the browser to open PDFs in the standalone reader.
  • Apply vendor and distribution patches (Adobe APSB07-01, APSB09-15, and the SUSE, Gentoo, Slackware, and Sun advisories listed).
  • Restrict users from following untrusted .pdf links and treat javascript: and res: URIs in PDF contexts as suspicious.
  • Keep browsers and plugins current, since the flaw spans Firefox, Internet Explorer 6 SP1, Chrome, and Opera versions listed.

Detection

  • Monitor browser and proxy logs for .pdf URLs containing javascript: or res: URIs, or FDF, XML, XFDF, and name= anchor parameters.
  • Alert on Acrobat Reader plugin process activity spawned from browser sessions that then makes unexpected network requests.
  • Hunt for known exploit URLs and payload patterns from the referenced public exploit write-ups in web and endpoint telemetry.
  • Track endpoint inventory for Acrobat Reader plugin versions below 8.0.0 (and the affected 7.x, 8.x, 9.x builds) and flag them for remediation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf
http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html
http://secunia.com/advisories/23483 Vendor Advisory
http://secunia.com/advisories/23691 Vendor Advisory
http://secunia.com/advisories/23812 Vendor Advisory
http://secunia.com/advisories/23877 Vendor Advisory
http://secunia.com/advisories/23882 Vendor Advisory
http://secunia.com/advisories/24457 Vendor Advisory
http://secunia.com/advisories/24533 Vendor Advisory
http://secunia.com/advisories/33754 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200701-16.xml
http://securityreason.com/securityalert/2090
http://securitytracker.com/id?1017469
http://securitytracker.com/id?1023007
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1
http://www.adobe.com/support/security/advisories/apsa07-01.html Vendor Advisory
http://www.adobe.com/support/security/advisories/apsa07-02.html
http://www.adobe.com/support/security/bulletins/apsb07-01.html
http://www.adobe.com/support/security/bulletins/apsb09-15.html
http://www.disenchant.ch/blog/hacking-with-browser-plugins/34 Exploit
http://www.gnucitizen.org/blog/danger-danger-danger/ ExploitVendor Advisory
http://www.gnucitizen.org/blog/universal-pdf-xss-after-party
http://www.kb.cert.org/vuls/id/815960 Third Party AdvisoryUS Government Resource
http://www.mozilla.org/security/announce/2007/mfsa2007-02.html
http://www.redhat.com/support/errata/RHSA-2007-0021.html
http://www.securityfocus.com/archive/1/455790/100/0/threaded Exploit
http://www.securityfocus.com/archive/1/455800/100/0/threaded
http://www.securityfocus.com/archive/1/455801/100/0/threaded
http://www.securityfocus.com/archive/1/455831/100/0/threaded Exploit
http://www.securityfocus.com/archive/1/455836/100/0/threaded
http://www.securityfocus.com/archive/1/455906/100/0/threaded
http://www.securityfocus.com/bid/21858
http://www.us-cert.gov/cas/techalerts/TA09-286B.html US Government Resource
http://www.vupen.com/english/advisories/2007/0032 Vendor Advisory
http://www.vupen.com/english/advisories/2007/0957 Vendor Advisory
http://www.vupen.com/english/advisories/2009/2898 Vendor Advisory
http://www.wisec.it/vulns.php?page=9 ExploitPatch

Track CVE-2007-0045 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0546Adobe Reader and Acrobat sandbox bypass allows privileged code executionAdobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reade…KEVEPSS 22%analysed9.8CVE-2013-3346Adobe Reader and Acrobat memory corruption allows code executionAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory.…KEVEPSS 79%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed9.8CVE-2011-2462Adobe Reader and Acrobat U3D memory corruption code executionAn out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The fla…KEVEPSS 89%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2014-0496Adobe Reader and Acrobat use-after-free code executionAdobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary …KEVEPSS 40%analysed8.8CVE-2011-0611Adobe Flash Player type confusion allows remote code executionAdobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Fl…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2007-0045), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.