Junglewise Threat Intelligence

CVE-2008-2992: Adobe Reader and Acrobat Input Validation Vulnerability

CVE-2008-2992 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2022-03-03

Technologies: Adobe Acrobat, Adobe Reader, Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

A stack-based buffer overflow exists in Adobe Acrobat and Reader due to improper input validation in the util.printf JavaScript function. Remote attackers can exploit this by enticing a user to open a crafted PDF file, potentially leading to arbitrary code execution.

Affected products

  • Adobe Acrobat 8.1.2 and earlier
  • Adobe Reader 8.1.2 and earlier

Timeline

  • 2008-11-04: disclosed: Related issue CVE-2008-1104 noted in description
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-03: exploited: Reported as exploited in the wild

Related threats