Vulnerability record · CVE-2010-2883 · published 9 September 2010
CVE-2010-2883: Adobe Reader and Acrobat CoolType.dll stack buffer overflow via SING table
Adobe · Acrobat
CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4 and 8.x before 8.2.5 on Windows and Mac OS X contains a stack-based buffer overflow triggered by a long field in a Smart INdependent Glyphlets (SING) table inside a TTF font embedded in a PDF. Opening a crafted PDF can crash the application or allow arbitrary code execution, and the flaw was exploited in the wild in September 2010.
Description
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with confirmed in-the-wild exploitation, a very high EPSS score, and it yields arbitrary code execution when a user opens a crafted PDF.
What it is
CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4 and 8.x before 8.2.5 on Windows and Mac OS X contains a stack-based buffer overflow triggered by a long field in a Smart INdependent Glyphlets (SING) table inside a TTF font embedded in a PDF. Opening a crafted PDF can crash the application or allow arbitrary code execution, and the flaw was exploited in the wild in September 2010.
Impact
An attacker who gets a victim to open a malicious PDF can execute arbitrary code in the context of the Reader/Acrobat process, or at minimum crash it. Successful code execution gives the attacker the user's privileges on the host.
Attack surface
Reached by opening a crafted PDF containing a malicious TTF font with a malformed SING table; no authentication is required, but user interaction (opening the file) is needed. The CVSS 3.1 vector is local with UI:R, reflecting the file-open trigger rather than a network service.
Exploitation
Listed in CISA KEV (added 2022-06-08) and described as exploited in the wild in September 2010; EPSS 30-day probability is 0.82485 (99.6th percentile), indicating high predicted exploitation activity. Reference tags are mostly vendor advisories and broken links, with no public exploit tag in this record.
What to do
- Patch first: upgrade Adobe Reader/Acrobat to 9.4 or 8.2.5 (or later) per Adobe APSB10-21, or apply the equivalent vendor updates for Linux distributions listed in the advisories.
- Disable or restrict JavaScript and embedded font handling in Reader/Acrobat where operationally possible.
- Block or sandbox PDF attachments at email and web gateways, and force PDFs to open in a hardened viewer rather than the default desktop reader.
- Remove or upgrade unsupported Reader/Acrobat 8.x and 9.x installations that cannot be patched.
- Apply the mitigations in the CISA KEV required action and track remediation against the 2022-06-22 due date for any remaining exposed systems.
Detection
- Hunt for Reader/Acrobat crashes or process terminations correlated with recently opened PDF files, especially from email or downloads.
- Monitor for child processes spawned by AcroRd32.exe or Acrobat.exe, which can indicate successful exploitation.
- Search file and mail telemetry for PDFs containing embedded TTF fonts with malformed or oversized SING tables.
- Alert on execution of known exploit artifacts or shellcode patterns associated with this CVE in endpoint telemetry.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2010-2883 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-2883 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-2883), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.