← Vulnerability feed

Vulnerability record · CVE-2009-3958 · published 13 January 2010

CVE-2009-3958: Adobe Reader and Acrobat getPlus Helper ActiveX stack buffer overflow

Adobe · Acrobat

The NOS Microsystems getPlus Helper ActiveX control (gp.ocx) shipped with Adobe Reader and Acrobat 9.x before 9.3 and 8.x before 8.2 contains multiple stack-based buffer overflows. The flaw is reached through unspecified initialization parameters and can corrupt memory in a way that may allow code execution. It matters because the affected control is installed alongside widely deployed Adobe Reader and Acrobat installations on Windows and Mac OS X.

10.0 CVSS 2.0 High EPSS 53% · top 1.1% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in the NOS Microsystems getPlus Helper ActiveX control before 1.6.2.49 in gp.ocx in the Download Manager in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow remote attackers to execute arbitrary code via unspecified initialization parameters.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityThe flaw is remotely reachable with no authentication and rated CVSS 10, and EPSS is in the 98.9th percentile, though it is not in KEV and no public exploit is tagged.

What it is

The NOS Microsystems getPlus Helper ActiveX control (gp.ocx) shipped with Adobe Reader and Acrobat 9.x before 9.3 and 8.x before 8.2 contains multiple stack-based buffer overflows. The flaw is reached through unspecified initialization parameters and can corrupt memory in a way that may allow code execution. It matters because the affected control is installed alongside widely deployed Adobe Reader and Acrobat installations on Windows and Mac OS X.

Impact

A remote attacker may execute arbitrary code in the context of the process hosting the ActiveX control, giving full control of the affected system. The CVSS vector rates complete confidentiality, integrity and availability impact.

Attack surface

The vector is network-reachable with no authentication (AV:N/AC:L/Au:N), and the flaw is in an ActiveX control, so it is typically reached by a user visiting a malicious or compromised web page that instantiates the control. User interaction is implied by the ActiveX delivery model, though the record does not state it explicitly.

Exploitation

The record is not listed in CISA KEV and no ransomware use is documented, but EPSS is high at 0.526 probability (98.9th percentile), indicating elevated likelihood of exploitation activity. Reference tags include only Patch, Vendor Advisory and US Government Resource, with no public exploit tag.

What to do

  • Update Adobe Reader and Acrobat to 9.3 or 8.2 (or later) per Adobe bulletin APSB10-02, which also addresses the getPlus Helper control.
  • Apply the getPlus Helper update to version 1.6.2.49 or later where the control is installed independently.
  • Disable or remove the getPlus Helper ActiveX control (gp.ocx) via Internet Explorer killbit or equivalent control-blocking policy on systems that do not need it.
  • Restrict browsing to trusted sites and enforce script/ActiveX controls policy for untrusted zones.
  • Track vendor and US-CERT advisories for any follow-up guidance on the getPlus control.

Detection

  • Inventory endpoints for gp.ocx and the getPlus Helper control, and flag versions below 1.6.2.49.
  • Monitor for processes loading gp.ocx, especially browser or Office processes spawning unexpected child processes.
  • Hunt for crash or exploit telemetry in browser processes consistent with stack buffer overflow in the getPlus control.
  • Review proxy and IDS logs for pages that instantiate the getPlus Helper ActiveX control from untrusted origins.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-3958 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0546Adobe Reader and Acrobat sandbox bypass allows privileged code executionAdobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reade…KEVEPSS 22%analysed9.8CVE-2013-3346Adobe Reader and Acrobat memory corruption allows code executionAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory.…KEVEPSS 79%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed9.8CVE-2011-2462Adobe Reader and Acrobat U3D memory corruption code executionAn out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The fla…KEVEPSS 89%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2014-0496Adobe Reader and Acrobat use-after-free code executionAdobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary …KEVEPSS 40%analysed8.8CVE-2011-0611Adobe Flash Player type confusion allows remote code executionAdobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Fl…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2009-3958), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.