Vulnerability record · CVE-2009-2990 · published 19 October 2009
CVE-2009-2990: Adobe Reader and Acrobat array index error allows code execution
Adobe · Acrobat
Adobe Reader and Acrobat contain an array index error (CWE-189) that can lead to arbitrary code execution. The flaw affects 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4. Because the vector is unspecified, the exact parsing path is unknown, but the impact is full code execution in the context of the user.
Description
Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitrary code via unspecified vectors.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS 9.3 and high EPSS indicate a severe, remotely exploitable flaw with likely active exploitation, though no KEV listing.
What it is
Adobe Reader and Acrobat contain an array index error (CWE-189) that can lead to arbitrary code execution. The flaw affects 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4. Because the vector is unspecified, the exact parsing path is unknown, but the impact is full code execution in the context of the user.
Impact
An attacker can execute arbitrary code with the privileges of the user running Adobe Reader or Acrobat. This can lead to complete compromise of the affected system.
Attack surface
The vulnerability is reachable remotely over the network (AV:N) with no authentication required (Au:N), but requires some user interaction (AC:M), typically opening a malicious PDF or visiting a crafted page. No further details on the exact vector are provided.
Exploitation
The CVE is not listed in CISA KEV, but EPSS is 0.68669 (99.3rd percentile), indicating a high likelihood of exploitation activity. No public exploit references are tagged in the record.
What to do
- Apply the vendor patch by upgrading to Adobe Reader/Acrobat 9.2 or 8.1.7 as specified in Adobe Security Bulletin APSB09-15.
- If immediate patching is not possible, disable JavaScript in Adobe Reader and Acrobat and enable Enhanced Security settings.
- Restrict the ability to open untrusted PDF files from email or web downloads until systems are patched.
- Consider using an alternative PDF viewer for untrusted documents as a temporary workaround.
Detection
- Monitor for unexpected child processes spawned by Adobe Reader or Acrobat (e.g., cmd.exe, powershell.exe).
- Detect PDF files with malformed array structures or unusual object streams using YARA or similar rules.
- Review endpoint logs for crashes or memory corruption in AcroRd32.exe or Acrobat.exe that may indicate exploitation attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-2990 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-2990), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.