CVE-2009-3459
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- September 29, 2009
- Published Date
- October 13, 2009
- Last Updated
- August 07, 2024
- Vendor
- Adobe
- Product
- Reader and Acrobat
- Description
- Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.
- Tags
- Exploited in the Wild
- Yes (2009-10-13 10:00:00 UTC) Source
metasploit_scanner
CVSS Scores
CVSS v2.0
9.3
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploit Status
References
http://secunia.com/advisories/36983
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6534
http://www.us-cert.gov/cas/techalerts/TA09-286B.html
http://securitytracker.com/id?1023007
http://www.adobe.com/support/security/bulletins/apsb09-15.html
http://www.iss.net/threats/348.html
http://www.vupen.com/english/advisories/2009/2851
http://isc.sans.org/diary.html?storyid=7300
http://blogs.adobe.com/psirt/2009/10/adobe_reader_and_acrobat_issue_1.html
http://www.securityfocus.com/bid/36600
http://www.vupen.com/english/advisories/2009/2898
https://exchange.xforce.ibmcloud.com/vulnerabilities/53691
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CVE | 2009-10-13 10:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/adobe_flatedecode_predictor02.rb | 2025-04-29 11:01:33 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
adobe_flatedecode_predictor02
Type: metasploit • Created: Unknown
Metasploit module for CVE-2009-3459
adobe_flatedecode_predictor02
Type: metasploit • Created: Unknown
Metasploit module for CVE-2009-3459
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel
-
Detected by Metasploit