Vulnerability record · CVE-2008-2549 · published 4 June 2008
CVE-2008-2549: Adobe Acrobat Reader malformed PDF crash and possible code execution
Adobe · Acrobat Reader
Adobe Acrobat Reader 8.1.2 and earlier, and versions before 7.1.1, mishandle a malformed PDF document, causing an application crash and possibly allowing arbitrary code execution. The flaw is remotely reachable and matters because PDFs are a routine, trusted file type, so a crafted document can be delivered through normal channels.
Description
Adobe Acrobat Reader 8.1.2 and earlier, and before 7.1.1, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed PDF document, as demonstrated by 2008-HI2.pdf.
AV:N/AC:M/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityCVSS 2.0 rates this MEDIUM (4.3) with only partial impact, but high EPSS and a public exploit raise concern for unpatched, legacy Reader installations.
What it is
Adobe Acrobat Reader 8.1.2 and earlier, and versions before 7.1.1, mishandle a malformed PDF document, causing an application crash and possibly allowing arbitrary code execution. The flaw is remotely reachable and matters because PDFs are a routine, trusted file type, so a crafted document can be delivered through normal channels.
Impact
An attacker can crash the Reader application and, per the description, possibly execute arbitrary code in the context of the user running Acrobat Reader.
Attack surface
Reached remotely by delivering a malformed PDF (demonstrated as 2008-HI2.pdf) to a victim; the CVSS vector AV:N/AC:M/Au:N indicates no authentication is required, but some user action such as opening the file is implied by the medium attack complexity.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high at roughly 0.53 (99th percentile) and a public Exploit-DB entry (5687) exists, indicating known public exploit material.
What to do
- Upgrade Acrobat Reader to a fixed release per Adobe bulletins APSB08-19 and APSB09-04; versions 8.1.2 and earlier and before 7.1.1 are affected.
- Apply vendor patches from downstream distributions (Red Hat RHSA-2008-0974, openSUSE, Oracle/Sun alerts) where Reader is packaged or bundled.
- Disable or restrict automatic opening of PDFs from untrusted sources and block PDF attachments at the mail gateway where feasible.
- Run Reader with reduced privileges and enable OS-level exploit mitigations (DEP/ASLR) to limit code execution impact.
Detection
- Monitor for Acrobat Reader crash events and unexpected process termination correlated with recently opened PDF files.
- Hunt for PDF files matching the known proof-of-concept name 2008-HI2.pdf or with malformed structure on endpoints and mail gateways.
- Alert on Reader spawning child processes or making unusual network connections after opening a document, which would suggest successful exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-2549 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-2549), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.