CVE-2009-3459

HIGH(8.8)KEVLikely Exploited

Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

Description

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.

KEV Information

Vendor
Adobe
Product
Acrobat and Reader
Date Added
May 20, 2026
Due Date
June 3, 2026
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
adobeacrobat>= 7.0, < 7.1.4; >= 8.0, < 8.1.7; >= 9.0, < 9.2
adobeacrobat reader>= 7.0, < 7.1.4; >= 8.0, < 8.1.7; >= 9.0, < 9.2

References

CVSS Score

8.8
HIGH(8.8)

EPSS Score

EPSS Score86.58%
EPSS Percentile99.7%

Dates

PublishedOctober 13, 2009
Last ModifiedJune 16, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.