← Vulnerability feed

Vulnerability record · CVE-2007-5659 · published 12 February 2008

CVE-2007-5659: Adobe Reader and Acrobat buffer overflow via crafted PDF JavaScript

Adobe · Acrobat

Adobe Reader and Acrobat 8.1.1 and earlier contain multiple buffer overflows triggered by a PDF file with long arguments passed to unspecified JavaScript methods. Successful exploitation allows arbitrary code execution in the context of the user opening the document. The record notes the issue might be subsumed by CVE-2008-0655, so the exact boundary of this flaw is not fully clear.

7.8 CVSS 3.1 High CISA KEV since 8 Jun 2022 EPSS 87% · top 0.2% CWE-120 · Classic buffer overflow
7.8CVSS 3.1 base score, v2 9.3
87%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
27References
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw gives code execution from a user-opened file, is in CISA KEV with a near-maximum EPSS score, but requires user interaction and affects only legacy Adobe versions.

What it is

Adobe Reader and Acrobat 8.1.1 and earlier contain multiple buffer overflows triggered by a PDF file with long arguments passed to unspecified JavaScript methods. Successful exploitation allows arbitrary code execution in the context of the user opening the document. The record notes the issue might be subsumed by CVE-2008-0655, so the exact boundary of this flaw is not fully clear.

Impact

An attacker gains arbitrary code execution on the victim's machine with the privileges of the user running Reader or Acrobat. That enables malware installation, data theft or further lateral movement from the workstation.

Attack surface

Reached by convincing a user to open a malicious PDF in Adobe Reader or Acrobat; the CVSS vector shows local access with user interaction required and no privileges needed. No authentication is required, and the description does not identify a network service path.

Exploitation

It is listed in CISA KEV (added 2022-06-08) with a required action to apply vendor updates, and EPSS gives a 30-day probability of 0.94024 (99.8th percentile), indicating high observed and predicted exploitation activity. No ransomware campaign use is recorded.

What to do

  • Apply the Adobe updates referenced in the vendor advisories (APSA08-01, APSB08-13) or later fixed versions.
  • If immediate patching is not possible, disable JavaScript execution in Adobe Reader and Acrobat.
  • Block or restrict untrusted PDF attachments and downloads at the mail gateway and web proxy.
  • Upgrade to a currently supported Adobe Reader/Acrobat release, since 8.1.1 is long out of support.
  • Apply the third-party fixes listed for Gentoo and Red Hat where those packaged versions are in use.

Detection

  • Monitor for Adobe Reader or Acrobat processes spawning child processes such as cmd.exe, powershell.exe or script interpreters.
  • Alert on Reader/Acrobat crashes or buffer-overflow-related faulting module events in endpoint telemetry.
  • Hunt for PDF files containing unusually long JavaScript method arguments or obfuscated script blocks in email and web download paths.
  • Review proxy and mail logs for PDFs delivered from untrusted sources to users running vulnerable Reader/Acrobat versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2007-5659 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Adobe Acrobat and Reader Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=657 Broken Link
http://secunia.com/advisories/29065 Broken Link
http://secunia.com/advisories/29205 Broken Link
http://secunia.com/advisories/30840 Broken Link
http://security.gentoo.org/glsa/glsa-200803-01.xml Third Party Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-239286-1 Broken Link
http://www.adobe.com/support/security/advisories/apsa08-01.html Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb08-13.html Vendor Advisory
http://www.kb.cert.org/vuls/id/666281 Third Party AdvisoryUS Government Resource
http://www.redhat.com/support/errata/RHSA-2008-0144.html Broken Link
http://www.us-cert.gov/cas/techalerts/TA08-043A.html Broken LinkThird Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2008/1966/references Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9813 Broken Link
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=657 Broken Link
http://secunia.com/advisories/29065 Broken Link
http://secunia.com/advisories/29205 Broken Link
http://secunia.com/advisories/30840 Broken Link
http://security.gentoo.org/glsa/glsa-200803-01.xml Third Party Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-239286-1 Broken Link
http://www.adobe.com/support/security/advisories/apsa08-01.html Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb08-13.html Vendor Advisory
http://www.kb.cert.org/vuls/id/666281 Third Party AdvisoryUS Government Resource
http://www.redhat.com/support/errata/RHSA-2008-0144.html Broken Link
http://www.us-cert.gov/cas/techalerts/TA08-043A.html Broken LinkThird Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2008/1966/references Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9813 Broken Link
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2007-5659 US Government Resource

Track CVE-2007-5659 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0546Adobe Reader and Acrobat sandbox bypass allows privileged code executionAdobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reade…KEVEPSS 22%analysed9.8CVE-2013-3346Adobe Reader and Acrobat memory corruption allows code executionAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory.…KEVEPSS 79%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed9.8CVE-2011-2462Adobe Reader and Acrobat U3D memory corruption code executionAn out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The fla…KEVEPSS 89%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2014-0496Adobe Reader and Acrobat use-after-free code executionAdobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary …KEVEPSS 40%analysed8.8CVE-2011-0611Adobe Flash Player type confusion allows remote code executionAdobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Fl…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2007-5659), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.