According to Symantec the first exploitation of the vulnerability was detected on 2008-12-14.
Exploit:Win32/CVE-2010-2883.A
Trojan horse Exploit_c.JLU (AVG)
Exploit.PDF.1533 (Dr.Web)
Exploit.PDF-JS.Gen(Sunbelt Software)
Bloodhound.Exploit.357 (Symantec).
Vulnerability details
Advisory: SB2010090802 - Remote code execution in Adobe Reader
Vulnerable component: Adobe Reader
CVE-ID: CVE-2010-2883
CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:H/RL:O/RC:C
CWE-ID: CWE-119 - Memory corruption
Description:
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to boundary error when handling specially crafted fonts within PDF document. A remote attacker can create a specially crafted PDF document, trick the victim into opening it, cause stack-based buffer overflow and execute arbitrary code on vulnerable system.
Successful exploitation of the vulnerability results in compromise of vulnerable system.
Note: this vulnerability is being actively exploited.
Public Exploits:
- Adobe CoolType - SING Table 'uniqueName' Stack Buffer Overflow (Metasploit) (2) [Exploit-DB]
- Adobe CoolType - SING Table 'uniqueName' Stack Buffer Overflow (Metasploit) (1) [Exploit-DB]
External links:
http://www.adobe.com/support/security/bulletins/apsb10-21.html
http://www.adobe.com/support/security/advisories/apsa10-02.html
https://blogs.forcepoint.com/security-labs/adobe-reader-0-day-vulnerability-cve-2010-2883
/Adobe+SING+table+parsing+exploit+CVE20102883+in+the+wild/9541/
https://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=23889
https://pentestn00b.wordpress.com/2010/09/15/new-adobe-0day-cve-2010-2883/
http://developers-club.com/posts/104137/
https://nakedsecurity.sophos.com/2010/09/08/adobe-advises-reader-acrobat-vulnerability/
https://forum.kaspersky.com/index.php?showtopic=184980
https://quequero.org/2014/09/pdf-analysis-of-nuclear-pack-ek-and-cve-2010-0188-cve-2013-2883/
https://users.ece.cmu.edu/~tdumitra/public_documents/bilge12_zero_day.pdf