PatchSiren

PatchSiren cyber security CVE debrief

CVE-2009-4324 Adobe CVE debrief

CVE-2009-4324 is a use-after-free vulnerability affecting Adobe Acrobat and Reader. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-06-08, with a remediation due date of 2022-06-22. Because it is on the KEV list, defenders should treat it as a priority issue and follow vendor update guidance without delay.

Vendor
Adobe
Product
Acrobat and Reader
CVSS
Unknown
CISA KEV
Listed
Original CVE published
2022-06-08
Original CVE updated
2022-06-08
Advisory published
2022-06-08
Advisory updated
2022-06-08

Who should care

Security teams, endpoint administrators, and vulnerability management teams responsible for Adobe Acrobat and Reader deployments should prioritize this CVE, especially where PDF handling is common across user workstations.

Technical summary

The supplied source corpus identifies CVE-2009-4324 as a use-after-free vulnerability in Adobe Acrobat and Reader. CISA’s KEV entry marks it as known exploited and directs organizations to apply updates per vendor instructions. No affected versions, attack conditions, or severity score were included in the supplied source data.

Defensive priority

High. The KEV listing means this issue should be prioritized for remediation within normal patch cycles and, where possible, accelerated ahead of other non-KEV work.

Recommended defensive actions

  • Inventory Adobe Acrobat and Reader installations across endpoints and virtual desktops.
  • Apply vendor-provided updates or remediation steps as directed by Adobe and CISA.
  • Verify patch deployment and confirm the affected software is no longer present on exposed systems.
  • Prioritize this CVE in vulnerability management workflows because it is listed in CISA’s KEV catalog.
  • Monitor endpoints for successful remediation and handle exceptions quickly if systems cannot be updated immediately.

Evidence notes

CISA’s Known Exploited Vulnerabilities JSON identifies the vulnerability as "Adobe Acrobat and Reader Use-After-Free Vulnerability" for vendor project Adobe and product Acrobat and Reader, with dateAdded 2022-06-08, dueDate 2022-06-22, and requiredAction "Apply updates per vendor instructions." The source metadata also points to the NVD record for CVE-2009-4324. No CVSS score or affected-version detail was included in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2009-4324 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2009-4324

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2009-4324 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2009-4324

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.