Vulnerability record · CVE-2010-0188 · published 22 February 2010
CVE-2010-0188: Adobe Reader and Acrobat unspecified flaw allows code execution
Adobe · Acrobat
Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 contain an unspecified vulnerability that can crash the application or possibly execute arbitrary code. The record gives no root cause, no affected code path and no exploit detail, so defenders must treat it as a memory-corruption-class flaw in a widely deployed document reader.
Description
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw is in CISA KEV with confirmed ransomware campaign use and an EPSS score above the 99th percentile, so it is being exploited and must be remediated immediately.
What it is
Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 contain an unspecified vulnerability that can crash the application or possibly execute arbitrary code. The record gives no root cause, no affected code path and no exploit detail, so defenders must treat it as a memory-corruption-class flaw in a widely deployed document reader.
Impact
An attacker who can get a crafted file processed gains the ability to crash the application or potentially run arbitrary code in the context of the user opening the document. Successful code execution would give the attacker the user's privileges on the workstation.
Attack surface
The CVSS 3.1 vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), which conflicts with the classic document-open scenario implied by the description; the record does not resolve this discrepancy. Reachability is therefore best described as local or file-based rather than remote network exploitation.
Exploitation
CVE-2010-0188 is listed in CISA KEV with a due date of 2022-03-24 and is flagged as used in known ransomware campaigns, and EPSS gives a 30-day probability of 0.88246 (99.8th percentile). No public exploit code or reference tag in this record explicitly confirms a working exploit, but KEV inclusion is authoritative evidence of exploitation in the wild.
What to do
- Upgrade Adobe Reader and Acrobat to 8.2.1 or 9.3.1 or later, or to a currently supported release, per Adobe bulletin APSB10-07.
- Apply the vendor errata for Linux distributions (for example Red Hat RHSA-2010-0114 and the openSUSE advisory) where Reader or Acrobat is packaged.
- If legacy 8.x/9.x Reader or Acrobat cannot be removed, restrict its use, block untrusted PDF sources and isolate the host from sensitive data.
- Enforce least privilege so a compromised reader process cannot write to system locations or reach high-value network shares.
Detection
- Hunt for Reader or Acrobat processes (AcroRd32.exe, Acrobat.exe) spawning child processes such as cmd.exe, powershell.exe or script hosts, which is abnormal for a PDF viewer.
- Monitor for crashes or abnormal termination of Reader and Acrobat followed by new process creation or outbound connections from the same host.
- Alert on PDF files written to temp or user download directories that are immediately opened by Reader, especially from email or web download sources.
- Review endpoint telemetry for the KEV-listed exploitation window and correlate with known ransomware precursor activity on hosts running unsupported Reader or Acrobat versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2010-0188 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-0188 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-0188), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.