Code execution in Adobe Reader and Adobe Acrobat - CVE-2010-1240
Published: January 21, 2017 / Updated: June 6, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system using social engineering attack.
The vulnerability exists due to unspecified error. A remote attacker can use social engineering attack to trick the victim into executing arbitrary code on vulnerable system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Adobe Acrobat
How to mitigate CVE-2010-1240
Adobe Reader 8.2.4 or 9.3.4
Adobe Acrobat 8.2.4 or 9.3.4
Links to Public Exploits and PoC-codes
- Exploit #5531 - Embedded-PDF (This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists of embedded payload. The exploit was made public as CVE-2010-1240. ) (June 6, 2021)
- Exploit #845 - Adobe PDF - Escape EXE Social Engineering (No JavaScript)(Metasploit) (March 18, 2020)
- Exploit #846 - Adobe PDF - Embedded EXE Social Engineering (Metasploit) (March 18, 2020)
- Exploit #847 - Adobe Reader - Escape From '.PDF' (March 18, 2020)
- Exploit #1642 - Adobe PDF Escape EXE Social Engineering (No JavaScript) (March 18, 2020)
- Exploit #1643 - Adobe PDF Embedded EXE Social Engineering (March 18, 2020)