Adobe.Reader.Javascript.newplayer

NameAdobe.Reader.Javascript.newplayer.Method.Code.Execution
Last Updated DateJan 28, 2010
Release DateDec 17, 2009
SeverityCritical
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against a zero-day vulnerability in Adobe Reader and Acrobat.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted PDF file that could allow remote attackers to execute arbitrary code.
Affected ProductsAdobe Reader 9.2 and earlier versions
Adobe Acrobat 9.2 and earlier versions
Recommended ActionsApply the patch supplied by the vendor:
http://www.adobe.com/support/security/bulletins/apsb10-02.html
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4324
Reference/shttp://www.securityfocus.com/bid/37331 (BugTraq)
http://www.adobe.com/support/security/advisories/apsa09-07.html
http://www.adobe.com/support/security/bulletins/apsb10-02.html
Reference: VID-18047