Junglewise Threat Intelligence

CVE-2009-3953: Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability

CVE-2009-3953 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-06-08

Technologies: Adobe Acrobat, Adobe Reader, Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

Adobe Acrobat and Reader contain an out-of-bounds write vulnerability in the Universal 3D (U3D) implementation. Remote attackers can execute arbitrary code via malformed U3D data in a PDF document, specifically related to the CLODProgressiveMeshDeclaration array boundary issue.

Affected products

  • Adobe Acrobat 9.x before 9.3, 8.x before 8.2, 7.x before 7.1.4
  • Adobe Reader 9.x before 9.3, 8.x before 8.2, 7.x before 7.1.4

Timeline

  • 2010-01-12: advisory: Adobe security bulletin APSB10-02 published
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-06-08: disclosed

Related threats