CVE-2009-3459
Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
Description
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.
Description as published by the source, in English.
Key facts
- Published
- 2009-10-13
- Last modified
- 2026-06-16
- Assigned by
- psirt@adobe.com
- CVSS vector
AV:N/AC:M/Au:N/C:C/I:C/A:C- Scored by
- nvd@nist.gov (NVD Primary)
- Probability of exploitation
-
86.6 %
among the highest of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Yes, see references
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-05-20, with a remediation deadline of 2026-06-03 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Adobe | Acrobat | ≥ 7.0, < 7.1.4 | Affected |
| Adobe | Acrobat | ≥ 8.0, < 8.1.7 | Affected |
| Adobe | Acrobat | ≥ 9.0, < 9.2 | Affected |
| Adobe | Acrobat Reader | ≥ 7.0, < 7.1.4 | Affected |
| Adobe | Acrobat Reader | ≥ 8.0, < 8.1.7 | Affected |
| Adobe | Acrobat Reader | ≥ 9.0, < 9.2 | Affected |
Weakness type
-
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations tha…
-
CWE-122: Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
References
- http://blogs.adobe.com/psirt/2009/10/adobe_reader_and_acrobat_issue_1.html
- http://isc.sans.org/diary.html?storyid=7300
- http://secunia.com/advisories/36983
- http://securitytracker.com/id?1023007=
- http://www.adobe.com/support/security/bulletins/apsb09-15.html
- http://www.iss.net/threats/348.html
- http://www.securityfocus.com/bid/36600
- http://www.us-cert.gov/cas/techalerts/TA09-286B.html
- http://www.vupen.com/english/advisories/2009/2851
- http://www.vupen.com/english/advisories/2009/2898
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53691
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A65…
- http://blogs.adobe.com/psirt/2009/10/adobe_reader_and_acrobat_issue_1.html
- http://isc.sans.org/diary.html?storyid=7300
- http://secunia.com/advisories/36983
- http://securitytracker.com/id?1023007=
- http://www.adobe.com/support/security/bulletins/apsb09-15.html
- http://www.iss.net/threats/348.html
- http://www.securityfocus.com/bid/36600
- http://www.us-cert.gov/cas/techalerts/TA09-286B.html
Related at Berigo
Articles
-
Almost a third of this week's listed vulnerabilities have no severity score
Same product
2026-08-25
The weekly vulnerability summary from CISA lists 3882 vulnerabilities for the week beginning 10 August. 1184 of them have no calculated severity scor…
-
Adobe fixes critical flaw scoring 10.0 in Campaign Classic
Same product
2026-08-03
Adobe published an update on 29 July 2026 for two vulnerabilities in Campaign Classic. CVE-2026-48449 scores 10.0 and can give code execution without…
-
Adobe patches twelve vulnerabilities in ColdFusion and Campaign Classic
Same product
2026-06-30
Adobe has published updates fixing twelve CVEs in ColdFusion and Adobe Campaign Classic, several allowing arbitrary code execution.
-
Adobe patches critical Acrobat and Reader flaw after exploitation
Same product
2026-04-13
A crafted PDF could bypass security mechanisms and run code. The flaw has been exploited in real attacks since at least November 2025.
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.