ZeroHour

CVE-2007-5659

KEVmass

Buffer Overflow in Adobe Acrobat and Reader via Malicious PDF JavaScript

CISA: Adobe Acrobat and Reader Buffer Overflow Vulnerability

CVSS
EPSS
94%p100
Published
KEV added
AI analysis

Adobe Acrobat and Reader contain a buffer overflow (CWE-119) in their handling of arguments passed to JavaScript methods when rendering PDF files. An attacker triggers the flaw by convincing a user to open a crafted PDF whose embedded JavaScript calls methods with overly long arguments, and no user privileges beyond viewing the file are required. Successful exploitation allows a remote attacker to execute arbitrary code in the context of the user running Acrobat or Reader. Anyone running the affected Acrobat or Reader versions (specific version ranges are not provided in the source data) is affected, with Adobe Reader historically being one of the most widely deployed desktop applications. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2022-06-08, confirming exploitation in the wild, and EPSS assigns a 94% probability of exploitation within 30 days (100th percentile); no public proof-of-concept is known and ransomware use is unknown.

What to do: Apply updates per vendor instructions by upgrading Acrobat and Reader to the patched releases Adobe made available for your version line, and audit the estate for legacy, unpatched Acrobat/Reader installs given the 2022 KEV listing. As an interim mitigation, disable or restrict JavaScript in the Acrobat/Reader preferences and treat PDFs from untrusted sources (email attachments, drive-by download sites, exploit-kit delivery channels) with caution.

Affected
Adobe Acrobat
Adobe Reader
Estimated exposure
masshundreds of millions of users/installations historically (Adobe Reader/Acrobat is among the most widely deployed desktop PDF viewers); current unpatched… — The estimate is based on the historical ubiquity of Adobe Reader/Acrobat, which has been distributed to hundreds of millions of users worldwide, making any remotely exploitable PDF-viewer flaw mass-scale by default.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods.

CISA Known Exploited Vulnerability
Affected
Adobe Acrobat and Reader
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Acrobat and Reader
Weakness
CWE-119

In the news