CVE-2010-0188
adobe acrobat, adobe acrobat reader
Published 22 Feb 2010 · updated 14 Aug 2026 · Analyzed
7.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Mar 2022, with a remediation deadline of 24 Mar 2022 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply updates per vendor instructions.
Description
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.
References
- lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html · Mailing List, Third Party Advisory
- secunia.com/advisories/38639 · Broken Link, Vendor Advisory
- secunia.com/advisories/38915 · Broken Link
- securitytracker.com/id?1023601 · Broken Link, Third Party Advisory, VDB Entry
- www.adobe.com/support/security/bulletins/apsb10-07.html · Broken Link, Vendor Advisory
- www.redhat.com/support/errata/RHSA-2010-0114.html · Broken Link, Vendor Advisory
- www.securityfocus.com/bid/38195 · Broken Link, Third Party Advisory, VDB Entry
- www.vupen.com/english/advisories/2010/0399 · Broken Link, Vendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/56297 · Third Party Advisory, VDB Entry
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8697 · Broken Link
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-0188 · US Government Resource