Vulnerability record · CVE-2009-0658 · published 20 February 2009
CVE-2009-0658: Adobe Reader and Acrobat buffer overflow via crafted PDF
Adobe · Acrobat
Adobe Reader 9.0 and earlier and Acrobat 9.0 and earlier contain a buffer overflow (CWE-119) reachable through a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream. Successful exploitation allows arbitrary code execution, and the flaw was exploited in the wild in February 2009 by Trojan.Pidief.E.
Description
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream, as exploited in the wild in February 2009 by Trojan.Pidief.E.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with confirmed in-the-wild exploitation and a very high EPSS score, though it requires the user to open a crafted PDF and affects only legacy Reader/Acrobat 9.0 and earlier.
What it is
Adobe Reader 9.0 and earlier and Acrobat 9.0 and earlier contain a buffer overflow (CWE-119) reachable through a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream. Successful exploitation allows arbitrary code execution, and the flaw was exploited in the wild in February 2009 by Trojan.Pidief.E.
Impact
An attacker can execute arbitrary code in the context of the user who opens the malicious PDF, giving full control of that process and potentially the host. The CVSS 3.1 vector rates confidentiality, integrity and availability impact as high.
Attack surface
The flaw is reached when a user opens a crafted PDF in the vulnerable Reader or Acrobat; the CVSS vector is AV:L/PR:N/UI:R, so no authentication is needed but user interaction (opening the file) is required. Delivery is typically via a malicious PDF file or link.
Exploitation
The description states the flaw was exploited in the wild in February 2009 by Trojan.Pidief.E, and an Exploit-DB entry exists; CISA KEV does not list it, while EPSS is very high (0.878 probability, 99.75th percentile).
What to do
- Upgrade Adobe Reader and Acrobat to a version later than 9.0 that contains the fix from Adobe bulletin APSB09-04.
- Apply vendor and distribution patches (Red Hat RHSA-2009-0376, openSUSE, Gentoo GLSA 200904-17, Sun) for any bundled or system copies of Reader/Acrobat.
- Disable or restrict JavaScript and embedded content in Reader/Acrobat where feasible, and block untrusted PDF attachments at the mail and web gateway.
- If the product cannot be patched, isolate or remove it from endpoints that handle untrusted documents.
Detection
- Hunt for Reader/Acrobat processes spawning unexpected child processes (cmd.exe, powershell, wscript) after a PDF is opened.
- Monitor for PDF files containing JBIG2 streams or malformed non-JavaScript function calls delivered via email or web download.
- Search endpoint and proxy logs for known Trojan.Pidief.E indicators and for the Exploit-DB 8090 sample hashes.
- Alert on crashes or abnormal exits of AcroRd32.exe/Acrobat.exe correlated with recently opened PDFs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-0658 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-0658), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.