CVE-2009-3459
KEVmassHeap-Based Buffer Overflow in Adobe Acrobat and Reader Enables RCE via PDFs
CISA: Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
Adobe Acrobat and Reader contain a heap-based buffer overflow (CWE-119) in the processing of PDF content that corrupts process memory. The flaw is triggered remotely when a user opens a specially crafted PDF file, requiring no authentication and only that the victim open or view the malicious document. Successful exploitation allows an attacker to execute arbitrary code on the victim's system with the privileges of the user running Acrobat or Reader. Anyone running an affected version of Adobe Acrobat or Reader is exposed, and because these PDF clients are near-ubiquitous on desktops, the potential affected population is very large. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-05-20, confirming active exploitation in the wild; EPSS assigns an 86.6% probability of exploitation within 30 days, while no public proof-of-concept is known and ransomware use has not been confirmed.
What to do: Inventory systems running Adobe Acrobat or Reader and upgrade to a patched version per Adobe's security advisory immediately, since the KEV listing invokes BOD 22-01 timelines for federal agencies. Until patched, filter or sandbox untrusted PDFs at email gateways and consider disabling PDF JavaScript in Reader where supported, a standard Adobe mitigation for this class of flaw. Verify installed versions against the vendor's affected-version list and monitor CISA and vendor advisories for updated indicators, noting ransomware use remains unconfirmed.
| Adobe Acrobat | — |
| Adobe Reader | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
- Affected
- Adobe Acrobat and Reader
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- Adobe
- Products
- Acrobat and Reader
- Weakness
- CWE-119