Vulnerability record · CVE-2008-2992 · published 4 November 2008
CVE-2008-2992: Adobe Acrobat and Reader util.printf Stack Buffer Overflow
Adobe · Acrobat
Adobe Acrobat and Reader 8.1.2 and earlier contain a stack-based buffer overflow reachable through the util.printf JavaScript function when it is passed a crafted format string argument. A malicious PDF can trigger the overflow and corrupt memory, making this a code execution flaw in a widely deployed document reader.
Description
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use, has a near-maximum EPSS score, and allows remote code execution through a common file type.
What it is
Adobe Acrobat and Reader 8.1.2 and earlier contain a stack-based buffer overflow reachable through the util.printf JavaScript function when it is passed a crafted format string argument. A malicious PDF can trigger the overflow and corrupt memory, making this a code execution flaw in a widely deployed document reader.
Impact
An attacker who gets the crafted PDF opened can execute arbitrary code in the context of the vulnerable application, giving full control of confidentiality, integrity and availability on the affected host.
Attack surface
The flaw is reached by opening a malicious PDF that calls util.printf with a crafted format string. The CVSS vector shows local access with user interaction required and no privileges needed, so the victim must open the file.
Exploitation
CVE-2008-2992 is listed in CISA KEV with known ransomware campaign use, and EPSS gives a 30-day probability of 0.98482 (99.9th percentile). Reference tags include an Exploit tag, indicating public exploit material exists.
What to do
- Apply the Adobe security bulletin APSB08-19 update or a later fixed version of Acrobat and Reader.
- Apply the Oracle Solaris and Red Hat errata listed in the references for affected bundled or platform components.
- Disable or restrict JavaScript execution in Acrobat and Reader where business use allows.
- Block untrusted PDF attachments at email and web gateways and require users to open PDFs only from trusted sources.
- Retire or isolate end-of-life Acrobat and Reader 8.1.2 and earlier installations that cannot be patched.
Detection
- Hunt for PDF files containing util.printf calls with long or malformed format string arguments.
- Monitor for Acrobat or Reader processes spawning child processes or making unexpected network connections after opening a PDF.
- Alert on crashes or memory corruption events in Acrobat and Reader, especially correlated with recently received PDF files.
- Search endpoint and email logs for PDFs matching known exploit samples tied to this CVE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2008-2992 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Adobe Reader and Acrobat Input Validation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-2992 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-2992), CISA KEV, FIRST EPSS (scores of 2026-09-18). This page is refreshed as NVD updates the record.