← Vulnerability feed

Vulnerability record · CVE-2009-0658 · published 20 February 2009

CVE-2009-0658: Adobe Reader and Acrobat buffer overflow via crafted PDF

Adobe · Acrobat

Adobe Reader 9.0 and earlier and Acrobat 9.0 and earlier contain a buffer overflow (CWE-119) reachable through a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream. Successful exploitation allows arbitrary code execution, and the flaw was exploited in the wild in February 2009 by Trojan.Pidief.E.

7.8 CVSS 3.1 High EPSS 88% · top 0.2% CWE-119 · Memory buffer overflow
7.8CVSS 3.1 base score, v2 9.3
88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
52References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream, as exploited in the wild in February 2009 by Trojan.Pidief.E.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRemote code execution with confirmed in-the-wild exploitation and a very high EPSS score, though it requires the user to open a crafted PDF and affects only legacy Reader/Acrobat 9.0 and earlier.

What it is

Adobe Reader 9.0 and earlier and Acrobat 9.0 and earlier contain a buffer overflow (CWE-119) reachable through a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream. Successful exploitation allows arbitrary code execution, and the flaw was exploited in the wild in February 2009 by Trojan.Pidief.E.

Impact

An attacker can execute arbitrary code in the context of the user who opens the malicious PDF, giving full control of that process and potentially the host. The CVSS 3.1 vector rates confidentiality, integrity and availability impact as high.

Attack surface

The flaw is reached when a user opens a crafted PDF in the vulnerable Reader or Acrobat; the CVSS vector is AV:L/PR:N/UI:R, so no authentication is needed but user interaction (opening the file) is required. Delivery is typically via a malicious PDF file or link.

Exploitation

The description states the flaw was exploited in the wild in February 2009 by Trojan.Pidief.E, and an Exploit-DB entry exists; CISA KEV does not list it, while EPSS is very high (0.878 probability, 99.75th percentile).

What to do

  • Upgrade Adobe Reader and Acrobat to a version later than 9.0 that contains the fix from Adobe bulletin APSB09-04.
  • Apply vendor and distribution patches (Red Hat RHSA-2009-0376, openSUSE, Gentoo GLSA 200904-17, Sun) for any bundled or system copies of Reader/Acrobat.
  • Disable or restrict JavaScript and embedded content in Reader/Acrobat where feasible, and block untrusted PDF attachments at the mail and web gateway.
  • If the product cannot be patched, isolate or remove it from endpoints that handle untrusted documents.

Detection

  • Hunt for Reader/Acrobat processes spawning unexpected child processes (cmd.exe, powershell, wscript) after a PDF is opened.
  • Monitor for PDF files containing JBIG2 streams or malformed non-JavaScript function calls delivered via email or web download.
  • Search endpoint and proxy logs for known Trojan.Pidief.E indicators and for the Exploit-DB 8090 sample hashes.
  • Alert on crashes or abnormal exits of AcroRd32.exe/Acrobat.exe correlated with recently opened PDFs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://isc.sans.org/diary.html?n&storyid=5902 Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00005.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html Third Party Advisory
http://osvdb.org/52073 Broken Link
http://secunia.com/advisories/33901 Third Party Advisory
http://secunia.com/advisories/34392 Third Party Advisory
http://secunia.com/advisories/34490 Third Party Advisory
http://secunia.com/advisories/34706 Third Party Advisory
http://secunia.com/advisories/34790 Third Party Advisory
http://security.gentoo.org/glsa/glsa-200904-17.xml Third Party Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-66-256788-1 Third Party Advisory
http://www.adobe.com/support/security/advisories/apsa09-01.html Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb09-04.html Vendor Advisory
http://www.kb.cert.org/vuls/id/905281 Third Party AdvisoryUS Government Resource
http://www.redhat.com/support/errata/RHSA-2009-0376.html Third Party Advisory
http://www.securityfocus.com/bid/33751 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1021739 Third Party AdvisoryVDB Entry
http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20090219 Third Party Advisory
http://www.symantec.com/security_response/writeup.jsp?docid=2009-021212-5523-99&tabid=2 Third Party Advisory
http://www.us-cert.gov/cas/techalerts/TA09-051A.html Third Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2009/0472 Third Party Advisory
http://www.vupen.com/english/advisories/2009/1019 Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/48825 VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5697 Tool Signature
https://www.exploit-db.com/exploits/8090 Third Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/8099 Third Party AdvisoryVDB Entry
http://isc.sans.org/diary.html?n&storyid=5902 Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00005.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html Third Party Advisory
http://osvdb.org/52073 Broken Link
http://secunia.com/advisories/33901 Third Party Advisory
http://secunia.com/advisories/34392 Third Party Advisory
http://secunia.com/advisories/34490 Third Party Advisory
http://secunia.com/advisories/34706 Third Party Advisory
http://secunia.com/advisories/34790 Third Party Advisory
http://security.gentoo.org/glsa/glsa-200904-17.xml Third Party Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-66-256788-1 Third Party Advisory
http://www.adobe.com/support/security/advisories/apsa09-01.html Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb09-04.html Vendor Advisory
http://www.kb.cert.org/vuls/id/905281 Third Party AdvisoryUS Government Resource

Track CVE-2009-0658 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0546Adobe Reader and Acrobat sandbox bypass allows privileged code executionAdobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reade…KEVEPSS 22%analysed9.8CVE-2013-3346Adobe Reader and Acrobat memory corruption allows code executionAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory.…KEVEPSS 79%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed9.8CVE-2011-2462Adobe Reader and Acrobat U3D memory corruption code executionAn out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The fla…KEVEPSS 89%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2014-0496Adobe Reader and Acrobat use-after-free code executionAdobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary …KEVEPSS 40%analysed8.8CVE-2011-0611Adobe Flash Player type confusion allows remote code executionAdobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Fl…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2009-0658), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.