← Vulnerability feed

Vulnerability record · CVE-2008-2549 · published 4 June 2008

CVE-2008-2549: Adobe Acrobat Reader malformed PDF crash and possible code execution

Adobe · Acrobat Reader

Adobe Acrobat Reader 8.1.2 and earlier, and versions before 7.1.1, mishandle a malformed PDF document, causing an application crash and possibly allowing arbitrary code execution. The flaw is remotely reachable and matters because PDFs are a routine, trusted file type, so a crafted document can be delivered through normal channels.

4.3 CVSS 2.0 Medium EPSS 53% · top 1.1%
4.3CVSS 2.0 base score
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
34References
16 Jun 2026Last modified by NVD

Description

Adobe Acrobat Reader 8.1.2 and earlier, and before 7.1.1, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed PDF document, as demonstrated by 2008-HI2.pdf.

AV:N/AC:M/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

medium priorityCVSS 2.0 rates this MEDIUM (4.3) with only partial impact, but high EPSS and a public exploit raise concern for unpatched, legacy Reader installations.

What it is

Adobe Acrobat Reader 8.1.2 and earlier, and versions before 7.1.1, mishandle a malformed PDF document, causing an application crash and possibly allowing arbitrary code execution. The flaw is remotely reachable and matters because PDFs are a routine, trusted file type, so a crafted document can be delivered through normal channels.

Impact

An attacker can crash the Reader application and, per the description, possibly execute arbitrary code in the context of the user running Acrobat Reader.

Attack surface

Reached remotely by delivering a malformed PDF (demonstrated as 2008-HI2.pdf) to a victim; the CVSS vector AV:N/AC:M/Au:N indicates no authentication is required, but some user action such as opening the file is implied by the medium attack complexity.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high at roughly 0.53 (99th percentile) and a public Exploit-DB entry (5687) exists, indicating known public exploit material.

What to do

  • Upgrade Acrobat Reader to a fixed release per Adobe bulletins APSB08-19 and APSB09-04; versions 8.1.2 and earlier and before 7.1.1 are affected.
  • Apply vendor patches from downstream distributions (Red Hat RHSA-2008-0974, openSUSE, Oracle/Sun alerts) where Reader is packaged or bundled.
  • Disable or restrict automatic opening of PDFs from untrusted sources and block PDF attachments at the mail gateway where feasible.
  • Run Reader with reduced privileges and enable OS-level exploit mitigations (DEP/ASLR) to limit code execution impact.

Detection

  • Monitor for Acrobat Reader crash events and unexpected process termination correlated with recently opened PDF files.
  • Hunt for PDF files matching the known proof-of-concept name 2008-HI2.pdf or with malformed structure on endpoints and mail gateways.
  • Alert on Reader spawning child processes or making unusual network connections after opening a document, which would suggest successful exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://download.oracle.com/sunalerts/1019937.1.html
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html
http://secunia.com/advisories/32700
http://secunia.com/advisories/32872
http://secunia.com/advisories/35163
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=800801
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=909609
http://www.adobe.com/support/security/bulletins/apsb08-19.html
http://www.adobe.com/support/security/bulletins/apsb09-04.html
http://www.redhat.com/support/errata/RHSA-2008-0974.html
http://www.securityfocus.com/bid/29420
http://www.securitytracker.com/id?1021140
http://www.us-cert.gov/cas/techalerts/TA08-309A.html US Government Resource
http://www.vupen.com/english/advisories/2008/3001
http://www.vupen.com/english/advisories/2009/0098
https://exchange.xforce.ibmcloud.com/vulnerabilities/42886
https://www.exploit-db.com/exploits/5687
http://download.oracle.com/sunalerts/1019937.1.html
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html
http://secunia.com/advisories/32700
http://secunia.com/advisories/32872
http://secunia.com/advisories/35163
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=800801
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=909609
http://www.adobe.com/support/security/bulletins/apsb08-19.html
http://www.adobe.com/support/security/bulletins/apsb09-04.html
http://www.redhat.com/support/errata/RHSA-2008-0974.html
http://www.securityfocus.com/bid/29420
http://www.securitytracker.com/id?1021140
http://www.us-cert.gov/cas/techalerts/TA08-309A.html US Government Resource
http://www.vupen.com/english/advisories/2008/3001
http://www.vupen.com/english/advisories/2009/0098
https://exchange.xforce.ibmcloud.com/vulnerabilities/42886
https://www.exploit-db.com/exploits/5687

Track CVE-2008-2549 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0546Adobe Reader and Acrobat sandbox bypass allows privileged code executionAdobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reade…KEVEPSS 22%analysed9.8CVE-2013-3346Adobe Reader and Acrobat memory corruption allows code executionAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory.…KEVEPSS 79%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed9.8CVE-2011-2462Adobe Reader and Acrobat U3D memory corruption code executionAn out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The fla…KEVEPSS 89%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2011-0611Adobe Flash Player type confusion allows remote code executionAdobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Fl…KEVEPSS 99%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed

Source: NIST National Vulnerability Database (record CVE-2008-2549), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.