Junglewise Threat Intelligence

CVE-2009-3459: Adobe Acrobat and Reader heap overflow in PDF parsing

CVE-2009-3459 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2026-05-20

Technologies: Adobe Acrobat, Adobe Reader. Vendors: Adobe.

Executive brief

Adobe Acrobat and Reader, widely used applications for viewing and managing PDF documents, are vulnerable to a critical security flaw. An attacker can exploit this by tricking a user into opening a specially crafted PDF file, which could lead to the attacker taking full control of the victim's computer. This vulnerability has been actively exploited in the wild to target users.

Technical details

A heap-based buffer overflow exists in Adobe Reader and Acrobat versions 7.x, 8.x, and 9.x. The vulnerability is triggered when the application processes a maliciously crafted PDF file, leading to memory corruption. This is a remote code execution (RCE) vulnerability that requires no authentication, though it does require user interaction (opening the file). Successful exploitation allows an attacker to execute arbitrary code with the privileges of the logged-in user. This flaw was notably exploited in the wild starting in October 2009. Patches are available in versions 7.1.4, 8.1.7, and 9.2.

Affected products

  • Adobe Acrobat 7.x before 7.1.4, 8.x before 8.1.7, 9.x before 9.2
  • Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, 9.x before 9.2

Timeline

  • 2009-10-13: disclosed
  • 2009-10-13: advisory
  • 2009-10-13: patched: Patches released in APSB09-15
  • 2009-10-01: exploited: Exploitation in the wild reported in October 2009

Related threats