← Vulnerability feed

Vulnerability record · CVE-2010-2883 · published 9 September 2010

CVE-2010-2883: Adobe Reader and Acrobat CoolType.dll stack buffer overflow via SING table

Adobe · Acrobat

CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4 and 8.x before 8.2.5 on Windows and Mac OS X contains a stack-based buffer overflow triggered by a long field in a Smart INdependent Glyphlets (SING) table inside a TTF font embedded in a PDF. Opening a crafted PDF can crash the application or allow arbitrary code execution, and the flaw was exploited in the wild in September 2010.

7.3 CVSS 3.1 High CISA KEV since 8 Jun 2022 EPSS 81% · top 0.4% CWE-787 · Out-of-bounds write
7.3CVSS 3.1 base score, v2 9.3
81%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
39References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with confirmed in-the-wild exploitation, a very high EPSS score, and it yields arbitrary code execution when a user opens a crafted PDF.

What it is

CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4 and 8.x before 8.2.5 on Windows and Mac OS X contains a stack-based buffer overflow triggered by a long field in a Smart INdependent Glyphlets (SING) table inside a TTF font embedded in a PDF. Opening a crafted PDF can crash the application or allow arbitrary code execution, and the flaw was exploited in the wild in September 2010.

Impact

An attacker who gets a victim to open a malicious PDF can execute arbitrary code in the context of the Reader/Acrobat process, or at minimum crash it. Successful code execution gives the attacker the user's privileges on the host.

Attack surface

Reached by opening a crafted PDF containing a malicious TTF font with a malformed SING table; no authentication is required, but user interaction (opening the file) is needed. The CVSS 3.1 vector is local with UI:R, reflecting the file-open trigger rather than a network service.

Exploitation

Listed in CISA KEV (added 2022-06-08) and described as exploited in the wild in September 2010; EPSS 30-day probability is 0.82485 (99.6th percentile), indicating high predicted exploitation activity. Reference tags are mostly vendor advisories and broken links, with no public exploit tag in this record.

What to do

  • Patch first: upgrade Adobe Reader/Acrobat to 9.4 or 8.2.5 (or later) per Adobe APSB10-21, or apply the equivalent vendor updates for Linux distributions listed in the advisories.
  • Disable or restrict JavaScript and embedded font handling in Reader/Acrobat where operationally possible.
  • Block or sandbox PDF attachments at email and web gateways, and force PDFs to open in a hardened viewer rather than the default desktop reader.
  • Remove or upgrade unsupported Reader/Acrobat 8.x and 9.x installations that cannot be patched.
  • Apply the mitigations in the CISA KEV required action and track remediation against the 2022-06-22 due date for any remaining exposed systems.

Detection

  • Hunt for Reader/Acrobat crashes or process terminations correlated with recently opened PDF files, especially from email or downloads.
  • Monitor for child processes spawned by AcroRd32.exe or Acrobat.exe, which can indicate successful exploitation.
  • Search file and mail telemetry for PDFs containing embedded TTF fonts with malformed or oversized SING tables.
  • Alert on execution of known exploit artifacts or shellcode patterns associated with this CVE in endpoint telemetry.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2010-2883 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blog.metasploit.com/2010/09/return-of-unpublished-adobe.html Broken Link
http://community.websense.com/blogs/securitylabs/archive/2010/09/10/brief-analysis-on-adobe-reader-sing-table-parsing-vu Broken Link
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00001.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html Broken Link
http://secunia.com/advisories/41340 Broken LinkVendor Advisory
http://secunia.com/advisories/43025 Broken LinkVendor Advisory
http://security.gentoo.org/glsa/glsa-201101-08.xml Third Party Advisory
http://www.adobe.com/support/security/advisories/apsa10-02.html Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb10-21.html Vendor Advisory
http://www.kb.cert.org/vuls/id/491991 Third Party AdvisoryUS Government Resource
http://www.redhat.com/support/errata/RHSA-2010-0743.html Broken Link
http://www.securityfocus.com/bid/43057 Broken LinkThird Party AdvisoryVDB Entry
http://www.turbolinux.co.jp/security/2011/TLSA-2011-2j.txt Broken Link
http://www.us-cert.gov/cas/techalerts/TA10-279A.html Third Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2010/2331 Broken LinkVendor Advisory
http://www.vupen.com/english/advisories/2011/0191 Broken LinkVendor Advisory
http://www.vupen.com/english/advisories/2011/0344 Broken LinkVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/61635 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11586 Broken Link
http://blog.metasploit.com/2010/09/return-of-unpublished-adobe.html Broken Link
http://community.websense.com/blogs/securitylabs/archive/2010/09/10/brief-analysis-on-adobe-reader-sing-table-parsing-vu Broken Link
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00001.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html Broken Link
http://secunia.com/advisories/41340 Broken LinkVendor Advisory
http://secunia.com/advisories/43025 Broken LinkVendor Advisory
http://security.gentoo.org/glsa/glsa-201101-08.xml Third Party Advisory
http://www.adobe.com/support/security/advisories/apsa10-02.html Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb10-21.html Vendor Advisory
http://www.kb.cert.org/vuls/id/491991 Third Party AdvisoryUS Government Resource
http://www.redhat.com/support/errata/RHSA-2010-0743.html Broken Link
http://www.securityfocus.com/bid/43057 Broken LinkThird Party AdvisoryVDB Entry
http://www.turbolinux.co.jp/security/2011/TLSA-2011-2j.txt Broken Link
http://www.us-cert.gov/cas/techalerts/TA10-279A.html Third Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2010/2331 Broken LinkVendor Advisory
http://www.vupen.com/english/advisories/2011/0191 Broken LinkVendor Advisory
http://www.vupen.com/english/advisories/2011/0344 Broken LinkVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/61635 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11586 Broken Link
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-2883 US Government Resource

Track CVE-2010-2883 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0546Adobe Reader and Acrobat sandbox bypass allows privileged code executionAdobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reade…KEVEPSS 22%analysed9.8CVE-2013-3346Adobe Reader and Acrobat memory corruption allows code executionAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory.…KEVEPSS 79%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed9.8CVE-2011-2462Adobe Reader and Acrobat U3D memory corruption code executionAn out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The fla…KEVEPSS 89%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2014-0496Adobe Reader and Acrobat use-after-free code executionAdobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary …KEVEPSS 40%analysed8.8CVE-2011-0611Adobe Flash Player type confusion allows remote code executionAdobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Fl…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2010-2883), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.