Vulnerability record · CVE-2010-1240 · published 5 April 2010
CVE-2010-1240: Adobe Reader and Acrobat Launch File dialog text field allows arbitrary local program execution
Adobe · Acrobat Reader
Adobe Reader and Acrobat 9.x before 9.3.3 and 8.x before 8.2.3 on Windows and Mac OS X fail to restrict the contents of a text field in the Launch File warning dialog. A remote attacker can craft a PDF whose dialog text misleads the user into approving execution of an arbitrary local program. This undermines the warning that is supposed to protect users from launching embedded files.
Description
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to trick users into executing an arbitrary local program that was specified in a PDF document, as demonstrated by a text field that claims that the Open button will enable the user to read an encrypted message.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS 9.3 and very high EPSS with public exploit material make this a serious risk, though exploitation requires user interaction and the affected versions are long superseded.
What it is
Adobe Reader and Acrobat 9.x before 9.3.3 and 8.x before 8.2.3 on Windows and Mac OS X fail to restrict the contents of a text field in the Launch File warning dialog. A remote attacker can craft a PDF whose dialog text misleads the user into approving execution of an arbitrary local program. This undermines the warning that is supposed to protect users from launching embedded files.
Impact
An attacker can cause an arbitrary local program specified in the PDF to run on the victim's machine, with the privileges of the user who opens the document. That gives code execution without a memory-corruption exploit, limited only by what the chosen program can do.
Attack surface
Reached by opening a malicious PDF in the affected Adobe Reader or Acrobat versions; no authentication is required, but the user must interact with the Launch File warning dialog. The CVSS vector AV:N/AC:M/Au:N confirms network delivery and medium complexity tied to user interaction.
Exploitation
No CISA KEV listing and no ransomware associations are recorded, but EPSS is 0.73617 (99.4th percentile) and references include an Exploit-tagged writeup, indicating public exploit material exists.
What to do
- Update Adobe Reader and Acrobat to 9.3.3 or 8.2.3 (or later) per Adobe bulletin APSB10-15.
- Disable or restrict the Launch File / embedded file execution feature in Reader and Acrobat where policy allows.
- Block or strip PDF embedded-file and launch actions at email and web gateways.
- Warn users not to approve Launch File dialogs from untrusted PDFs and train them on the misleading-dialog technique.
- Retire or isolate end-of-life Reader/Acrobat 8.x and 9.x installations that cannot be patched.
Detection
- Monitor process creation events where a PDF reader spawns cmd.exe, powershell.exe, wscript.exe, or other unexpected child processes.
- Search email and web proxy logs for PDFs containing /Launch, /EmbeddedFile, or /OpenAction entries.
- Alert on Adobe Reader or Acrobat processes making outbound network connections or writing executables to disk.
- Review endpoint telemetry for Reader/Acrobat versions below 9.3.3 or 8.2.3 still in use.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-1240 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-1240), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.