Published: 15/09/2008 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A certain ActiveX control in Adobe Acrobat 9, when used with Microsoft Windows Vista and Internet Explorer 7, allows remote malicious users to cause a denial of service (browser crash) via an src property value with an invalid acroie:// URL.

Affected Products

Vendor Product Versions


<!-- Jeremy Brown (0xjbrown41@gmailcom/jbrownsecblogspotcom) Adobe Acrobat 9 Remote DoS (--) Tested on AA9/IE7/Vista I can't seem to reproduce this on XP! Oh well Of course the most popular app for reading pdfs is SfS/SfI :) Basically it will crash with any uri that adobe doesn't like Also interesting: try with file ...