Vulnerability record · CVE-2008-0655 · published 7 February 2008
CVE-2008-0655: Adobe Reader and Acrobat unspecified memory corruption flaws
Adobe · Acrobat
Adobe Reader and Acrobat before 8.1.2 contain multiple unspecified vulnerabilities with unknown impact and attack vectors. The record gives no technical detail on the underlying flaws, but the CVSS vector indicates remote code execution potential with high confidentiality, integrity and availability impact. Because the flaws are unspecified, defenders cannot scope affected code paths beyond the version boundary.
Description
Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is in CISA KEV with high EPSS and a CVSS of 8.8, but the record lacks technical detail and the affected versions are long superseded.
What it is
Adobe Reader and Acrobat before 8.1.2 contain multiple unspecified vulnerabilities with unknown impact and attack vectors. The record gives no technical detail on the underlying flaws, but the CVSS vector indicates remote code execution potential with high confidentiality, integrity and availability impact. Because the flaws are unspecified, defenders cannot scope affected code paths beyond the version boundary.
Impact
An attacker who successfully triggers the flaws could achieve full compromise of confidentiality, integrity and availability on the victim's system, consistent with the CVSS 3.1 base score of 8.8. The record does not describe the specific gain beyond this generic impact.
Attack surface
The vector is network-reachable with no privileges required, but user interaction is required, consistent with a victim opening a crafted PDF or visiting attacker-controlled content in the affected products. No authentication is needed on the attacker side.
Exploitation
The vulnerability is listed in CISA KEV with a 2022-06-08 addition date, and EPSS shows a 30-day probability of roughly 0.39 at the 98.5th percentile, indicating observed exploitation and elevated likelihood. A reference is tagged Exploit, though the record does not describe the exploit itself.
What to do
- Upgrade Adobe Reader and Acrobat to 8.1.2 or later, or to a currently supported release, per the vendor advisory.
- Apply the vendor and third-party patches referenced in the advisory, including Linux distribution updates for bundled Reader.
- Disable or restrict JavaScript and non-essential plug-ins in Reader/Acrobat where business use allows.
- Enforce opening PDFs only from trusted sources and block untrusted PDF attachments at the mail and web gateway.
- Retire or isolate end-of-life Reader/Acrobat versions that cannot be patched.
Detection
- Monitor for Reader/Acrobat process crashes or abnormal child processes spawned from AcroRd32.exe or acroread.
- Alert on PDF files written to disk or opened from temp, mail cache or browser download directories shortly before a Reader crash.
- Hunt for network connections or file writes originating from Reader/Acrobat processes to unusual destinations.
- Review endpoint logs for exploitation indicators around the KEV due date window and correlate with patch state of Reader/Acrobat.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2008-0655 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Adobe Acrobat and Reader Unspecified Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-0655 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-0655), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.