Vulnerability record · CVE-2007-5659 · published 12 February 2008
CVE-2007-5659: Adobe Reader and Acrobat buffer overflow via crafted PDF JavaScript
Adobe · Acrobat
Adobe Reader and Acrobat 8.1.1 and earlier contain multiple buffer overflows triggered by a PDF file with long arguments passed to unspecified JavaScript methods. Successful exploitation allows arbitrary code execution in the context of the user opening the document. The record notes the issue might be subsumed by CVE-2008-0655, so the exact boundary of this flaw is not fully clear.
Description
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw gives code execution from a user-opened file, is in CISA KEV with a near-maximum EPSS score, but requires user interaction and affects only legacy Adobe versions.
What it is
Adobe Reader and Acrobat 8.1.1 and earlier contain multiple buffer overflows triggered by a PDF file with long arguments passed to unspecified JavaScript methods. Successful exploitation allows arbitrary code execution in the context of the user opening the document. The record notes the issue might be subsumed by CVE-2008-0655, so the exact boundary of this flaw is not fully clear.
Impact
An attacker gains arbitrary code execution on the victim's machine with the privileges of the user running Reader or Acrobat. That enables malware installation, data theft or further lateral movement from the workstation.
Attack surface
Reached by convincing a user to open a malicious PDF in Adobe Reader or Acrobat; the CVSS vector shows local access with user interaction required and no privileges needed. No authentication is required, and the description does not identify a network service path.
Exploitation
It is listed in CISA KEV (added 2022-06-08) with a required action to apply vendor updates, and EPSS gives a 30-day probability of 0.94024 (99.8th percentile), indicating high observed and predicted exploitation activity. No ransomware campaign use is recorded.
What to do
- Apply the Adobe updates referenced in the vendor advisories (APSA08-01, APSB08-13) or later fixed versions.
- If immediate patching is not possible, disable JavaScript execution in Adobe Reader and Acrobat.
- Block or restrict untrusted PDF attachments and downloads at the mail gateway and web proxy.
- Upgrade to a currently supported Adobe Reader/Acrobat release, since 8.1.1 is long out of support.
- Apply the third-party fixes listed for Gentoo and Red Hat where those packaged versions are in use.
Detection
- Monitor for Adobe Reader or Acrobat processes spawning child processes such as cmd.exe, powershell.exe or script interpreters.
- Alert on Reader/Acrobat crashes or buffer-overflow-related faulting module events in endpoint telemetry.
- Hunt for PDF files containing unusually long JavaScript method arguments or obfuscated script blocks in email and web download paths.
- Review proxy and mail logs for PDFs delivered from untrusted sources to users running vulnerable Reader/Acrobat versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2007-5659 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Adobe Acrobat and Reader Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-5659 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-5659), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.