Adobe Reader and Acrobat versions 9.x before 9.3.3 and 8.x before 8.2.3 on Windows and Mac OS X fail to restrict the contents of a text field in the Launch File warning dialog. This allows a remote attacker to craft a PDF that manipulates the dialog text, misleading users about the action performed by the Open button, and thereby tricking them into executing an arbitrary local program specified in the PDF.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
This repository is a proof-of-concept (PoC) exploit for CVE-2010-1240, a critical vulnerability in Adobe Reader and Acrobat (versions prior to 9.3.3 and 8.2.3) that allows arbitrary code execution via malicious PDF Launch Actions. The main file, pdf_generator.py, is a Python script that generates a minimal PDF file containing a Launch Action configured to execute a user-specified PowerShell command when opened in a vulnerable version of Adobe Reader/Acrobat on Windows. The script allows customization of the payload and output filename via command-line arguments. The exploit relies on social engineering to convince the user to approve the Launch Action dialog, after which the specified PowerShell command is executed. The repository contains a README with detailed usage instructions, technical background, and references. No network endpoints or external IPs are hardcoded; the only fingerprintable endpoint is the use of 'powershell.exe' as the execution target within the PDF. The exploit is intended for educational and research purposes only.
This repository contains a single Metasploit exploit module targeting Adobe Reader (<= 9.3.3) on Windows XP SP3. The module, 'adobe_pdf_embedded_exe_nojs.rb', generates a malicious PDF file that embeds an arbitrary EXE payload in a non-standard, hex-encoded format. When the victim opens the PDF, a launch action triggers a command that decodes and writes the EXE to the victim's %TEMP% directory, then executes it. The exploit does not require JavaScript to be enabled in the PDF reader, increasing its effectiveness. The module is designed for social engineering attacks, requiring the attacker to deliver the crafted PDF to the victim and convince them to open it. The code is operational and leverages Metasploit's payload generation and fileformat exploitation capabilities. Key fingerprintable endpoints include the output PDF file ('evil.pdf'), the embedded EXE ('msf.exe'), and temporary files used during exploitation ('%TEMP%\msf.exe', '1.vbs').
This repository contains a single Metasploit module: 'adobe_pdf_embedded_exe.rb', which targets Adobe Reader (v8.x, v9.x) on Windows platforms via CVE-2010-1240. The module allows an attacker to embed a Metasploit-generated EXE payload into a PDF file. The attacker supplies an input PDF (template.pdf by default) and a payload; the module creates a malicious PDF (evil.pdf by default) that, when opened by a victim, executes the embedded EXE. The exploit is designed for social engineering attacks, requiring the victim to open the crafted PDF. The code is mature and weaponized, supporting customizable payloads and robust error handling for PDF parsing. No network endpoints are hardcoded; the main fingerprintable artifacts are the input and output PDF file paths. The module is part of the Metasploit framework and leverages its payload generation and fileformat exploitation capabilities.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.