CVE-2009-1493
EXPLOITEDAdobe Reader 9.1, 8.1.4, 7.1.1 and earlier - Remote Code Execution via customDictionaryOpen JavaScript Method
Title source: llmExploitation Summary
CVE-2009-1493 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Arr1val.
AI-analyzed exploit summary This exploit targets a vulnerability in Adobe Reader by leveraging a heap spray technique to execute arbitrary shellcode. It uses a custom dictionary function to trigger the exploit, leading to remote code execution.
Description
The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.
Exploits (1)
This exploit targets a vulnerability in Adobe Reader by leveraging a heap spray technique to execute arbitrary shellcode. It uses a custom dictionary function to trigger the exploit, leading to remote code execution.