Vulnerability record · CVE-2009-4324 · published 15 December 2009
CVE-2009-4324: Adobe Reader and Acrobat Doc.media.newPlayer use-after-free code execution
Adobe · Acrobat
Adobe Reader and Acrobat 9.x before 9.3 and 8.x before 8.2 on Windows and Mac OS X contain a use-after-free in the Doc.media.newPlayer method in Multimedia.api. A crafted PDF using ZLib compressed streams can trigger the flaw and execute arbitrary code. It was exploited in the wild in December 2009, making it a high-risk client-side document flaw.
Description
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a remotely reachable code-execution flaw in widely deployed document software, listed in CISA KEV with very high EPSS, though exploitation requires the user to open a crafted PDF.
What it is
Adobe Reader and Acrobat 9.x before 9.3 and 8.x before 8.2 on Windows and Mac OS X contain a use-after-free in the Doc.media.newPlayer method in Multimedia.api. A crafted PDF using ZLib compressed streams can trigger the flaw and execute arbitrary code. It was exploited in the wild in December 2009, making it a high-risk client-side document flaw.
Impact
An attacker who gets a victim to open a malicious PDF can execute arbitrary code in the context of the Reader/Acrobat process. That typically gives the attacker the user's privileges on the host, enabling further compromise.
Attack surface
Reached by opening a crafted PDF file in a vulnerable Reader or Acrobat installation; the CVSS vector shows local access with user interaction required (UI:R) and no privileges required (PR:N). No authentication is needed, but the victim must open the document.
Exploitation
CISA KEV lists it as exploited in the wild, and EPSS is 0.81933 (99.6th percentile). Reference tags include Exploit, and the description states it was exploited in the wild in December 2009.
What to do
- Update Adobe Reader and Acrobat to 9.3 or 8.2 or later as directed by Adobe advisories APSA09-07 and APSB10-02.
- Apply vendor updates for SUSE/openSUSE packages where Acrobat/Reader components are present.
- Disable or restrict JavaScript and multimedia/Flash content in Reader and Acrobat where operationally possible.
- Block or sandbox untrusted PDF attachments at email and web gateways, and enforce Protected View/Protected Mode.
- Retire or isolate end-of-life Reader/Acrobat versions that cannot be patched.
Detection
- Hunt for Reader/Acrobat processes spawning child processes such as cmd.exe, powershell.exe, or wscript.exe.
- Monitor for PDF files containing ZLib compressed streams and references to Doc.media.newPlayer or Multimedia.api.
- Review endpoint and email gateway logs for PDFs matching known exploit samples or the Metasploit adobe_media_newplayer module.
- Alert on unexpected network connections originating from Reader/Acrobat processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2009-4324 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Adobe Acrobat and Reader Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-4324 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-4324), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.