CVE-2009-3459

HIGH(8.8)KEVWahrscheinlich ausgenutzt

Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

Beschreibung

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.

KEV-Informationen

Hersteller
Adobe
Produkt
Acrobat and Reader
Hinzugefügt am
20. Mai 2026
Fälligkeitsdatum
3. Juni 2026
Erforderliche Maßnahme
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS-Score

Vektorstring
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HIm Rechner öffnen
Angriffsvektor
NETWORK
Angriffskomplexität
LOW
Erforderliche Privilegien
NONE
Benutzerinteraktion
REQUIRED
Scope
UNCHANGED
Vertraulichkeitsauswirkung
HIGH
Integritätsauswirkung
HIGH
Verfügbarkeitsauswirkung
HIGH
Ausnutzbarkeitsscore
2.8
Auswirkungsscore
5.9

CWEs

Betroffene Produkte

HerstellerProduktVersion
adobeacrobat>= 7.0, < 7.1.4; >= 8.0, < 8.1.7; >= 9.0, < 9.2
adobeacrobat reader>= 7.0, < 7.1.4; >= 8.0, < 8.1.7; >= 9.0, < 9.2

Referenzen

CVSS-Score

8.8
HIGH(8.8)

EPSS-Score

EPSS-Score86.58%
EPSS-Perzentil99.7%

Daten

Veröffentlicht13. Oktober 2009
Zuletzt geändert16. Juni 2026
StatusAnalyzed
CVSS-Versionv3.1

Hilfe beim Schwachstellenmanagement?

Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.