← Vulnerability feed

Vulnerability record · CVE-2009-3459 · published 13 October 2009

CVE-2009-3459: Adobe Reader and Acrobat heap buffer overflow via crafted PDF

Adobe · Acrobat

Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted PDF file. Successful exploitation causes memory corruption that can lead to arbitrary code execution. The flaw was exploited in the wild in October 2009 and is now listed in CISA KEV.

8.8 CVSS 3.1 High CISA KEV since 20 May 2026 EPSS 87% · top 0.3% CWE-119 · Memory buffer overflowCWE-122 · Heap-based buffer overflow
8.8CVSS 3.1 base score, v2 9.3
87%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
25References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw allows remote code execution with user interaction, was exploited in the wild, and is in CISA KEV with a very high EPSS score.

What it is

Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted PDF file. Successful exploitation causes memory corruption that can lead to arbitrary code execution. The flaw was exploited in the wild in October 2009 and is now listed in CISA KEV.

Impact

An attacker can execute arbitrary code in the context of the user running Reader or Acrobat, giving full control of the affected process and potentially the host. CVSS 3.1 scores confidentiality, integrity and availability impact as High.

Attack surface

Reached remotely by delivering a malicious PDF that the victim opens in Adobe Reader or Acrobat; the vector is network-based with user interaction required and no privileges needed. No authentication is required on the attacker's side.

Exploitation

Exploitation in the wild was reported in October 2009, and CISA added the CVE to KEV with a 2026-06-03 remediation due date. EPSS is 0.86583 (99.7th percentile), indicating very high predicted exploitation activity.

What to do

  • Patch Adobe Reader and Acrobat to 7.1.4, 8.1.7, 9.2 or later per Adobe APSB09-15; if patching is not possible, discontinue use of the affected versions.
  • Disable JavaScript in Adobe Reader and Acrobat and enable Enhanced Security settings to reduce PDF attack surface.
  • Block or sandbox PDF rendering where feasible, and enforce least privilege so a compromised Reader process cannot write broadly.
  • Apply CISA BOD 22-01 guidance for cloud services and track KEV remediation deadlines.
  • Restrict untrusted PDF delivery through email and web gateways, and warn users against opening unexpected PDF attachments.

Detection

  • Monitor for Adobe Reader or Acrobat process crashes and abnormal child processes spawned from reader_sl, AcroRd32 or Acrobat.exe.
  • Inspect PDF files for malformed object streams or embedded JavaScript that trigger heap corruption patterns, using YARA or PDF parser rules.
  • Review endpoint telemetry for code execution or file writes originating from Reader/Acrobat in user-writable directories.
  • Hunt for known exploit PDF hashes and network indicators associated with the October 2009 in-the-wild campaign.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2009-3459 to the Known Exploited Vulnerabilities catalog on 20 May 2026 as "Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 3 June 2026.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blogs.adobe.com/psirt/2009/10/adobe_reader_and_acrobat_issue_1.html Broken LinkVendor Advisory
http://isc.sans.org/diary.html?storyid=7300 Not Applicable
http://secunia.com/advisories/36983 Vendor Advisory
http://securitytracker.com/id?1023007 Broken Link
http://www.adobe.com/support/security/bulletins/apsb09-15.html PatchVendor Advisory
http://www.iss.net/threats/348.html Broken Link
http://www.securityfocus.com/bid/36600 Broken Link
http://www.us-cert.gov/cas/techalerts/TA09-286B.html US Government Resource
http://www.vupen.com/english/advisories/2009/2851 Vendor Advisory
http://www.vupen.com/english/advisories/2009/2898 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/53691 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6534 Broken Link
http://blogs.adobe.com/psirt/2009/10/adobe_reader_and_acrobat_issue_1.html Broken LinkVendor Advisory
http://isc.sans.org/diary.html?storyid=7300 Not Applicable
http://secunia.com/advisories/36983 Vendor Advisory
http://securitytracker.com/id?1023007 Broken Link
http://www.adobe.com/support/security/bulletins/apsb09-15.html PatchVendor Advisory
http://www.iss.net/threats/348.html Broken Link
http://www.securityfocus.com/bid/36600 Broken Link
http://www.us-cert.gov/cas/techalerts/TA09-286B.html US Government Resource
http://www.vupen.com/english/advisories/2009/2851 Vendor Advisory
http://www.vupen.com/english/advisories/2009/2898 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/53691 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6534 Broken Link
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-3459 US Government Resource

Track CVE-2009-3459 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0546Adobe Reader and Acrobat sandbox bypass allows privileged code executionAdobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reade…KEVEPSS 22%analysed9.8CVE-2013-3346Adobe Reader and Acrobat memory corruption allows code executionAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory.…KEVEPSS 79%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed9.8CVE-2011-2462Adobe Reader and Acrobat U3D memory corruption code executionAn out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The fla…KEVEPSS 89%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2014-0496Adobe Reader and Acrobat use-after-free code executionAdobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary …KEVEPSS 40%analysed8.8CVE-2011-0611Adobe Flash Player type confusion allows remote code executionAdobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Fl…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2009-3459), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.