Junglewise Threat Intelligence

CVE-2009-0927: Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability

CVE-2009-0927 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2022-03-25

Technologies: Adobe Acrobat, Adobe Reader, Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

A stack-based buffer overflow in Adobe Reader and Acrobat allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab object. This vulnerability stems from improper input validation in a JavaScript method.

Affected products

  • Adobe Reader 9 before 9.1, 8 before 8.1.3, and 7 before 7.1.1
  • Adobe Acrobat 9 before 9.1, 8 before 8.1.3, and 7 before 7.1.1

Timeline

  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-25: disclosed
  • 2009-03-25: exploited: Reported as exploited in the wild in 2009 per historical context and CISA KEV status.

Related threats