CVE-2010-1240

EXPLOITED

Adobe PDF Embedded EXE Social Engineering

Title source: metasploit

Description

Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to trick users into executing an arbitrary local program that was specified in a PDF document, as demonstrated by a text field that claims that the Open button will enable the user to read an encrypted message.

Exploits (9)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/16682
exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/16671
exploitdb WORKING POC VERIFIED
by Didier Stevens · textlocalwindows
https://www.exploit-db.com/exploits/11987
nomisec WRITEUP 69 stars
by Jasmoon99 · poc
https://github.com/Jasmoon99/Embedded-PDF
nomisec WORKING POC 7 stars
by omarothmann · poc
https://github.com/omarothmann/Embedded-Backdoor-Connection
nomisec WORKING POC 1 stars
by asepsaepdin · poc
https://github.com/asepsaepdin/CVE-2010-1240
nomisec WORKING POC
by 12345qwert123456 · client-side
https://github.com/12345qwert123456/CVE-2010-1240
metasploit WORKING POC EXCELLENT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/adobe_pdf_embedded_exe.rb
metasploit WORKING POC EXCELLENT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/adobe_pdf_embedded_exe_nojs.rb

Scores

EPSS 0.9140
EPSS Percentile 99.7%

Details

VulnCheck KEV 2016-05-16
CWE
CWE-264
Status published
Products (1)
adobe/acrobat_reader 9.3.1
Published Apr 05, 2010
Tracked Since Feb 18, 2026