CVE-2009-3459
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- September 29, 2009
- Published Date
- October 13, 2009
- Last Updated
- May 21, 2026
- Vendor
- Adobe
- Product
- Reader and Acrobat
- Description
- Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.
- Tags
- Exploitation
- active
- Technical Impact
- total
- Exploited in the Wild
- Yes (2009-10-13 10:00:00 UTC) Source
metasploit
cisa
CVSS Scores
CVSS v3.1
8.8 - HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
9.3
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
SSVC Information
Exploit Status
References
http://secunia.com/advisories/36983
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6534
http://www.us-cert.gov/cas/techalerts/TA09-286B.html
http://securitytracker.com/id?1023007
http://www.adobe.com/support/security/bulletins/apsb09-15.html
http://www.iss.net/threats/348.html
http://www.vupen.com/english/advisories/2009/2851
http://isc.sans.org/diary.html?storyid=7300
http://blogs.adobe.com/psirt/2009/10/adobe_reader_and_acrobat_issue_1.html
http://www.securityfocus.com/bid/36600
http://www.vupen.com/english/advisories/2009/2898
https://exchange.xforce.ibmcloud.com/vulnerabilities/53691
Known Exploited Vulnerability Information
| Source | Added Date |
|---|---|
| CVE | 2009-10-13 10:00:00 UTC |
Scanner Integrations
| Scanner | URL | Date Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/adobe_flatedecode_predictor02.rb | 2025-04-29 10:58:59 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
adobe_flatedecode_predictor02
Type: metasploit • Created: Unknown
Metasploit module for CVE-2009-3459
adobe_flatedecode_predictor02
Type: metasploit • Created: Unknown
Metasploit module for CVE-2009-3459
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel
-
Detected by Metasploit