← Vulnerability feed

Vulnerability record · CVE-2010-1240 · published 5 April 2010

CVE-2010-1240: Adobe Reader and Acrobat Launch File dialog text field allows arbitrary local program execution

Adobe · Acrobat Reader

Adobe Reader and Acrobat 9.x before 9.3.3 and 8.x before 8.2.3 on Windows and Mac OS X fail to restrict the contents of a text field in the Launch File warning dialog. A remote attacker can craft a PDF whose dialog text misleads the user into approving execution of an arbitrary local program. This undermines the warning that is supposed to protect users from launching embedded files.

9.3 CVSS 2.0 High EPSS 74% · top 0.5% CWE-264 · Permissions and access controls
9.3CVSS 2.0 base score
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to trick users into executing an arbitrary local program that was specified in a PDF document, as demonstrated by a text field that claims that the Open button will enable the user to read an encrypted message.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 9.3 and very high EPSS with public exploit material make this a serious risk, though exploitation requires user interaction and the affected versions are long superseded.

What it is

Adobe Reader and Acrobat 9.x before 9.3.3 and 8.x before 8.2.3 on Windows and Mac OS X fail to restrict the contents of a text field in the Launch File warning dialog. A remote attacker can craft a PDF whose dialog text misleads the user into approving execution of an arbitrary local program. This undermines the warning that is supposed to protect users from launching embedded files.

Impact

An attacker can cause an arbitrary local program specified in the PDF to run on the victim's machine, with the privileges of the user who opens the document. That gives code execution without a memory-corruption exploit, limited only by what the chosen program can do.

Attack surface

Reached by opening a malicious PDF in the affected Adobe Reader or Acrobat versions; no authentication is required, but the user must interact with the Launch File warning dialog. The CVSS vector AV:N/AC:M/Au:N confirms network delivery and medium complexity tied to user interaction.

Exploitation

No CISA KEV listing and no ransomware associations are recorded, but EPSS is 0.73617 (99.4th percentile) and references include an Exploit-tagged writeup, indicating public exploit material exists.

What to do

  • Update Adobe Reader and Acrobat to 9.3.3 or 8.2.3 (or later) per Adobe bulletin APSB10-15.
  • Disable or restrict the Launch File / embedded file execution feature in Reader and Acrobat where policy allows.
  • Block or strip PDF embedded-file and launch actions at email and web gateways.
  • Warn users not to approve Launch File dialogs from untrusted PDFs and train them on the misleading-dialog technique.
  • Retire or isolate end-of-life Reader/Acrobat 8.x and 9.x installations that cannot be patched.

Detection

  • Monitor process creation events where a PDF reader spawns cmd.exe, powershell.exe, wscript.exe, or other unexpected child processes.
  • Search email and web proxy logs for PDFs containing /Launch, /EmbeddedFile, or /OpenAction entries.
  • Alert on Adobe Reader or Acrobat processes making outbound network connections or writing executables to disk.
  • Review endpoint telemetry for Reader/Acrobat versions below 9.3.3 or 8.2.3 still in use.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-1240 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0546Adobe Reader and Acrobat sandbox bypass allows privileged code executionAdobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reade…KEVEPSS 22%analysed9.8CVE-2013-3346Adobe Reader and Acrobat memory corruption allows code executionAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory.…KEVEPSS 79%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed9.8CVE-2011-2462Adobe Reader and Acrobat U3D memory corruption code executionAn out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The fla…KEVEPSS 89%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2011-0611Adobe Flash Player type confusion allows remote code executionAdobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Fl…KEVEPSS 99%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed

Source: NIST National Vulnerability Database (record CVE-2010-1240), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.