CVE-2009-3459
Adobe Acrobat and Reader: Heap-Based Buffer Overflow
As of , CVE-2009-3459 in Adobe Acrobat and Reader is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 20 May 2026
- US federal deadline
- 3 June 202614 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.87Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- Public exploit
- 2 Metasploit modules and 2 Exploit-DB entries (2 verified)
- Fix
- Vendor advice: web.archive.orgLinks below, from CISA's entry.
What CISA says to do
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA's required action
What the flaw is
Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
CISA's description
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.
The CVE record's description, from adobe
- CVE published
- 13 October 2009
- Assigned by
- adobe
- CVSS
- 8.8 High (CVSS 3.1, from CISA-ADP)
- CWE-122
- Heap-based Buffer Overflow
- CWE-119
- Improper Restriction of Operations within the Bounds of a Memory Buffer
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- no
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- Exploit-DB published an exploit (EDB-ID 16546).
- Exploit-DB published an exploit (EDB-ID 16652).
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: Adobe FlateDecode Stream Predictor 02 Integer Overflowexploit module, rank good
- Metasploit: Adobe FlateDecode Stream Predictor 02 Integer Overflowexploit module, rank good
- Exploit-DB: Adobe - FlateDecode Stream Predictor 02 Integer Overflow (Metasploit) (2)EDB-ID 16652, verified by Exploit-DB, 25 September 2010
- Exploit-DB: Adobe - FlateDecode Stream Predictor 02 Integer Overflow (Metasploit) (1)EDB-ID 16546, verified by Exploit-DB, 20 September 2010
Acrobat and Reader: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2007-5659Buffer Overflow | Adobe Acrobat and Reader | Patch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| CVE-2009-3953Universal 3D Remote Code Execution | Adobe Acrobat and Reader | Patch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry | 0.83 | ||
| CVE-2009-4324Use-After-Free | Adobe Acrobat and Reader | Patch this weekMetasploit module; EPSS 0.82; verified Exploit-DB entry | 0.82 | ||
| CVE-2010-2883Stack-Based Buffer Overflow | Adobe Acrobat and Reader | Patch this weekMetasploit module; EPSS 0.81; verified Exploit-DB entry | 0.81 | ||
| CVE-2008-2992Reader and Acrobat Input Validation | Adobe Acrobat and Reader | Patch this weekRansomware use; Metasploit module; EPSS 0.98; verified Exploit-DB entry | 0.98 | ||
| CVE-2023-21608Use-After-Free | Adobe Acrobat and Reader | Patch this weekEPSS 0.61 | 0.61 | ||
| CVE-2021-21017Heap-based Buffer Overflow | Adobe Acrobat and Reader | Patch this weekEPSS 0.86 | 0.86 | ||
| CVE-2021-28550Use-After-Free | Adobe Acrobat and Reader | Patch this weekEPSS 0.52 | 0.52 | ||
| CVE-2008-0655Unspecified | Adobe Acrobat and Reader | Patch soon | 0.38 | ||
| CVE-2018-4990Double Free | Adobe Acrobat and Reader | Patch soon | 0.36 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org