KEVIntel
8.8
CVSS
High

CVE-2009-3459

PUBLISHED

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute...

6076 days faster than CISA KEV

Exploited in the wild PoC available Remote Low complexity
Vendor
Adobe
Product
Reader and Acrobat
Published
Oct 13, 2009
EPSS
88.1% · 100% pctl

Automate this intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.

Description

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.

cisa metasploit

Weaknesses (CWE)

  • Improper Restriction of Operations within the Bounds of a Memory Buffer

  • Heap-based Buffer Overflow

CVSS scores

CVSS v3.1 8.8 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2.0 9.3 High

AV:N/AC:M/Au:N/C:C/I:C/A:C

Exploitation status

Exploited in the wild

Recorded 2009-10-13 10:00:00 UTC · CVE

Proof of concept available

Recorded 2025-04-28 15:02:37 UTC

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CVE First 2009-10-13 10:00 UTC
CISA 2026-06-02 14:00 UTC

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

adobe_flatedecode_predictor02

metasploit · Created Unknown

Metasploit module for CVE-2009-3459

adobe_flatedecode_predictor02

metasploit · Created Unknown

Metasploit module for CVE-2009-3459

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Proof of Concept Exploit Available

  • Detected by Metasploit

  • KEV confirmed by CISA