ZeroHour

CVE-2009-0927

KEVmass

Stack-Based Buffer Overflow in Adobe Reader and Acrobat Enables Remote Code Execution

CISA: Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability

CVSS
EPSS
97%p100
Published
KEV added
AI analysis

CVE-2009-0927 is a stack-based buffer overflow (improper input validation, CWE-20) in Adobe Reader and Adobe Acrobat that allows remote attackers to execute arbitrary code on the victim's system. The flaw is triggered when the PDF handling code in these products processes malicious input, typically via a specially crafted PDF document delivered through email, the web, or exploit kits. Successful exploitation gives an attacker the ability to run arbitrary code, generally with the privileges of the user running the PDF application. Any user or endpoint running an affected version of Adobe Reader or Acrobat is exposed, and given the near-universal deployment of these PDF tools the potential population is very large. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25) with a required action to apply vendor updates, and EPSS assigns a 96.6% probability of exploitation within 30 days, though no public proof-of-concept is known.

What to do: Apply updates per vendor instructions: upgrade all affected Adobe Reader and Acrobat installations to a patched release as required by the CISA KEV listing. As an interim mitigation, disable or restrict JavaScript in PDF files (the Acrobat JavaScript blocklist framework introduced around this period addresses this vector) and block PDFs from untrusted sources. Inventory endpoints for outdated Reader/Acrobat versions, prioritizing systems that open PDFs from email and the web.

Affected
Adobe Reader and Adobe Acrobat
Estimated exposure
masshundreds of millions of users (Adobe Reader was the dominant PDF viewer on desktops during the exploitation period) — Adobe Reader and Acrobat were near-ubiquitous PDF viewers bundled or installed on the overwhelming majority of Windows desktops in the 2009-2010 era, implying an affected install base in the hundreds of millions, though the exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.

CISA Known Exploited Vulnerability
Affected
Adobe Reader and Acrobat
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Reader and Acrobat
Weakness
CWE-20

In the news