Vulnerability record · CVE-2009-3953 · published 13 January 2010
CVE-2009-3953: Adobe Reader and Acrobat U3D Out-of-Bounds Write Code Execution
Adobe · Acrobat
Adobe Reader and Acrobat fail to properly validate U3D data in PDF documents, causing an out-of-bounds write in the CLODProgressiveMeshDeclaration handling. A malformed U3D stream can corrupt memory and lead to arbitrary code execution. This is a distinct flaw from CVE-2009-2994.
Description
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than CVE-2009-2994.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw is remotely reachable, leads to arbitrary code execution, is listed in CISA KEV as actively exploited, and has a very high EPSS score.
What it is
Adobe Reader and Acrobat fail to properly validate U3D data in PDF documents, causing an out-of-bounds write in the CLODProgressiveMeshDeclaration handling. A malformed U3D stream can corrupt memory and lead to arbitrary code execution. This is a distinct flaw from CVE-2009-2994.
Impact
An attacker can execute arbitrary code in the context of the affected application, giving full control of the process and potentially the host. Successful exploitation can lead to data theft, installation of malware, or further lateral movement.
Attack surface
The flaw is reached remotely by opening a crafted PDF containing malformed U3D data. No authentication is required, but user interaction (opening the file) is needed per the CVSS vector.
Exploitation
CISA KEV lists this as actively exploited with a 2022-06-08 addition, and EPSS shows a 30-day probability of 0.83855 (99.676th percentile). A public Metasploit module exists for the Windows fileformat vector, confirming weaponized exploitation.
What to do
- Apply the Adobe security bulletin APSB10-02 updates to Reader and Acrobat (9.3, 8.2, 7.1.4 or later).
- Apply vendor patches for SUSE/openSUSE Linux Enterprise packages referenced in the advisories.
- Disable or restrict U3D/3D content rendering in Reader and Acrobat where the feature is not required.
- Block or sandbox PDF attachments from untrusted sources at the email and web gateway.
- Retire or isolate end-of-life Reader/Acrobat versions that cannot be patched.
Detection
- Hunt for PDF files containing U3D streams with malformed CLODProgressiveMeshDeclaration structures using YARA or PDF parsing tools.
- Monitor for Reader/Acrobat processes spawning child processes such as cmd.exe, powershell.exe, or wscript.exe.
- Alert on crashes or memory corruption events in AcroRd32.exe/Acrobat.exe tied to PDF opens.
- Review proxy and email logs for PDFs matching known Metasploit adobe_u3d_meshdecl payload characteristics.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2009-3953 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-3953 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-3953), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.