Vulnerability record · CVE-2009-3459 · published 13 October 2009
CVE-2009-3459: Adobe Reader and Acrobat heap buffer overflow via crafted PDF
Adobe · Acrobat
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted PDF file. Successful exploitation causes memory corruption that can lead to arbitrary code execution. The flaw was exploited in the wild in October 2009 and is now listed in CISA KEV.
Description
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw allows remote code execution with user interaction, was exploited in the wild, and is in CISA KEV with a very high EPSS score.
What it is
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted PDF file. Successful exploitation causes memory corruption that can lead to arbitrary code execution. The flaw was exploited in the wild in October 2009 and is now listed in CISA KEV.
Impact
An attacker can execute arbitrary code in the context of the user running Reader or Acrobat, giving full control of the affected process and potentially the host. CVSS 3.1 scores confidentiality, integrity and availability impact as High.
Attack surface
Reached remotely by delivering a malicious PDF that the victim opens in Adobe Reader or Acrobat; the vector is network-based with user interaction required and no privileges needed. No authentication is required on the attacker's side.
Exploitation
Exploitation in the wild was reported in October 2009, and CISA added the CVE to KEV with a 2026-06-03 remediation due date. EPSS is 0.86583 (99.7th percentile), indicating very high predicted exploitation activity.
What to do
- Patch Adobe Reader and Acrobat to 7.1.4, 8.1.7, 9.2 or later per Adobe APSB09-15; if patching is not possible, discontinue use of the affected versions.
- Disable JavaScript in Adobe Reader and Acrobat and enable Enhanced Security settings to reduce PDF attack surface.
- Block or sandbox PDF rendering where feasible, and enforce least privilege so a compromised Reader process cannot write broadly.
- Apply CISA BOD 22-01 guidance for cloud services and track KEV remediation deadlines.
- Restrict untrusted PDF delivery through email and web gateways, and warn users against opening unexpected PDF attachments.
Detection
- Monitor for Adobe Reader or Acrobat process crashes and abnormal child processes spawned from reader_sl, AcroRd32 or Acrobat.exe.
- Inspect PDF files for malformed object streams or embedded JavaScript that trigger heap corruption patterns, using YARA or PDF parser rules.
- Review endpoint telemetry for code execution or file writes originating from Reader/Acrobat in user-writable directories.
- Hunt for known exploit PDF hashes and network indicators associated with the October 2009 in-the-wild campaign.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2009-3459 to the Known Exploited Vulnerabilities catalog on 20 May 2026 as "Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 3 June 2026.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-3459 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-3459), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.