ZeroHour

CVE-2008-2992

KEV ransomwaremass

Adobe Acrobat and Reader JavaScript Input Validation Flaw Enables Remote Code Execution

CISA: Adobe Reader and Acrobat Input Validation Vulnerability

CVSS
EPSS
98%p100
Published
KEV added
AI analysis

Adobe Acrobat and Reader contain an input validation flaw (CWE-119, memory corruption) in a JavaScript method — historically the util.printf() JavaScript function — that fails to safely handle crafted arguments. An attacker triggers the flaw by getting a user to open a specially crafted PDF containing malicious JavaScript, which can corrupt memory and allow code execution on the victim's machine. Successful exploitation yields remote code execution with the privileges of the logged-in user, typically used to deliver malware; the related headlines indicate this flaw was folded into exploit kits and spam-driven malware campaigns of the era. Anyone running a vulnerable version of Adobe Acrobat or Reader (specific version ranges were not provided in the source data) with PDF JavaScript enabled is affected. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2022-03-03 with known ransomware use, and EPSS assigns it a 98.5% probability of exploitation within 30 days.

What to do: Apply updated versions of Acrobat and Reader per Adobe's instructions, as required by the CISA KEV listing. As an interim mitigation, disable or restrict JavaScript in Acrobat/Reader preferences (a JavaScript blocklist/allowlist approach, consistent with Adobe's JavaScript Blocklist Framework), and caution users against opening unsolicited PDFs, since exploitation has occurred via exploit kits, spam campaigns, and ransomware delivery. Check endpoints for unpatched Acrobat/Reader installs and confirm remediation against the CISA KEV deadline.

Affected
Adobe Acrobat
Adobe Reader
Estimated exposure
massHundreds of millions of desktop users (an estimate — Adobe Reader held roughly 80–90%+ of the PDF-reader market in the 2008–2010 era and was bundled on vast… — Adobe Reader's near-dominant PDF market share and ubiquitous desktop bundling mean the potentially affected install base is on the order of hundreds of millions of users, though the count of still-vulnerable installations today is unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.

CISA Known Exploited Vulnerability
Affected
Adobe Acrobat and Reader
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
Adobe
Products
Acrobat and Reader
Weakness
CWE-119

In the news