← Vulnerability feed

Vulnerability record · CVE-2008-2992 · published 4 November 2008

CVE-2008-2992: Adobe Acrobat and Reader util.printf Stack Buffer Overflow

Adobe · Acrobat

Adobe Acrobat and Reader 8.1.2 and earlier contain a stack-based buffer overflow reachable through the util.printf JavaScript function when it is passed a crafted format string argument. A malicious PDF can trigger the overflow and corrupt memory, making this a code execution flaw in a widely deployed document reader.

7.8 CVSS 3.1 High CISA KEV since 3 Mar 2022 Known ransomware use EPSS 98% · top 0.1% CWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score, v2 9.3
98%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
55References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with known ransomware use, has a near-maximum EPSS score, and allows remote code execution through a common file type.

What it is

Adobe Acrobat and Reader 8.1.2 and earlier contain a stack-based buffer overflow reachable through the util.printf JavaScript function when it is passed a crafted format string argument. A malicious PDF can trigger the overflow and corrupt memory, making this a code execution flaw in a widely deployed document reader.

Impact

An attacker who gets the crafted PDF opened can execute arbitrary code in the context of the vulnerable application, giving full control of confidentiality, integrity and availability on the affected host.

Attack surface

The flaw is reached by opening a malicious PDF that calls util.printf with a crafted format string. The CVSS vector shows local access with user interaction required and no privileges needed, so the victim must open the file.

Exploitation

CVE-2008-2992 is listed in CISA KEV with known ransomware campaign use, and EPSS gives a 30-day probability of 0.98482 (99.9th percentile). Reference tags include an Exploit tag, indicating public exploit material exists.

What to do

  • Apply the Adobe security bulletin APSB08-19 update or a later fixed version of Acrobat and Reader.
  • Apply the Oracle Solaris and Red Hat errata listed in the references for affected bundled or platform components.
  • Disable or restrict JavaScript execution in Acrobat and Reader where business use allows.
  • Block untrusted PDF attachments at email and web gateways and require users to open PDFs only from trusted sources.
  • Retire or isolate end-of-life Acrobat and Reader 8.1.2 and earlier installations that cannot be patched.

Detection

  • Hunt for PDF files containing util.printf calls with long or malformed format string arguments.
  • Monitor for Acrobat or Reader processes spawning child processes or making unexpected network connections after opening a PDF.
  • Alert on crashes or memory corruption events in Acrobat and Reader, especially correlated with recently received PDF files.
  • Search endpoint and email logs for PDFs matching known exploit samples tied to this CVE.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2008-2992 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Adobe Reader and Acrobat Input Validation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://download.oracle.com/sunalerts/1019937.1.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html Mailing ListThird Party Advisory
http://osvdb.org/49520 Broken Link
http://secunia.com/advisories/29773 Broken LinkVendor Advisory
http://secunia.com/advisories/32700 Broken LinkVendor Advisory
http://secunia.com/advisories/32872 Broken LinkVendor Advisory
http://secunia.com/advisories/35163 Broken LinkVendor Advisory
http://secunia.com/secunia_research/2008-14/ Broken LinkVendor Advisory
http://securityreason.com/securityalert/4549 Broken LinkExploit
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=800801 Broken Link
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=909609 Broken Link
http://www.adobe.com/support/security/bulletins/apsb08-19.html Broken LinkPatchVendor Advisory
http://www.coresecurity.com/content/adobe-reader-buffer-overflow Third Party Advisory
http://www.kb.cert.org/vuls/id/593409 Third Party AdvisoryUS Government Resource
http://www.redhat.com/support/errata/RHSA-2008-0974.html Broken LinkPatch
http://www.securityfocus.com/archive/1/498027/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/498032/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/498055/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/30035 Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/32091 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1021140 Broken LinkThird Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA08-309A.html Broken LinkThird Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2008/3001 Broken LinkVendor Advisory
http://www.vupen.com/english/advisories/2009/0098 Broken LinkVendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-08-072/ Third Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/6994 Third Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/7006 ExploitThird Party AdvisoryVDB Entry
http://download.oracle.com/sunalerts/1019937.1.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html Mailing ListThird Party Advisory
http://osvdb.org/49520 Broken Link
http://secunia.com/advisories/29773 Broken LinkVendor Advisory
http://secunia.com/advisories/32700 Broken LinkVendor Advisory
http://secunia.com/advisories/32872 Broken LinkVendor Advisory
http://secunia.com/advisories/35163 Broken LinkVendor Advisory
http://secunia.com/secunia_research/2008-14/ Broken LinkVendor Advisory
http://securityreason.com/securityalert/4549 Broken LinkExploit
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=800801 Broken Link
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=909609 Broken Link
http://www.adobe.com/support/security/bulletins/apsb08-19.html Broken LinkPatchVendor Advisory
http://www.coresecurity.com/content/adobe-reader-buffer-overflow Third Party Advisory

Track CVE-2008-2992 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-14871Oracle Solaris PAM out-of-bounds write allows remote unauthenticated takeoverOracle Solaris 10 and 11 contain an out-of-bounds write (CWE-787) in the Pluggable Authentication Module component, reachable over the network withou…KEVEPSS 80%analysed9.8CVE-2014-0546Adobe Reader and Acrobat sandbox bypass allows privileged code executionAdobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reade…KEVEPSS 22%analysed9.8CVE-2013-3346Adobe Reader and Acrobat memory corruption allows code executionAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory.…KEVEPSS 79%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed9.8CVE-2011-2462Adobe Reader and Acrobat U3D memory corruption code executionAn out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The fla…KEVEPSS 89%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2019-3010Oracle Solaris XScreenSaver local privilege escalationA flaw in the XScreenSaver component of Oracle Solaris 11 allows a low-privileged user with a local logon to escalate privileges and take over the sy…KEVEPSS 13%analysed

Source: NIST National Vulnerability Database (record CVE-2008-2992), CISA KEV, FIRST EPSS (scores of 2026-09-18). This page is refreshed as NVD updates the record.