ZeroHour

CVE-2009-3459

KEVmass

Heap-Based Buffer Overflow in Adobe Acrobat and Reader Enables RCE via PDFs

CISA: Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

CVSS
EPSS
87%p100
Published
KEV added
AI analysis

Adobe Acrobat and Reader contain a heap-based buffer overflow (CWE-119) in the processing of PDF content that corrupts process memory. The flaw is triggered remotely when a user opens a specially crafted PDF file, requiring no authentication and only that the victim open or view the malicious document. Successful exploitation allows an attacker to execute arbitrary code on the victim's system with the privileges of the user running Acrobat or Reader. Anyone running an affected version of Adobe Acrobat or Reader is exposed, and because these PDF clients are near-ubiquitous on desktops, the potential affected population is very large. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-05-20, confirming active exploitation in the wild; EPSS assigns an 86.6% probability of exploitation within 30 days, while no public proof-of-concept is known and ransomware use has not been confirmed.

What to do: Inventory systems running Adobe Acrobat or Reader and upgrade to a patched version per Adobe's security advisory immediately, since the KEV listing invokes BOD 22-01 timelines for federal agencies. Until patched, filter or sandbox untrusted PDFs at email gateways and consider disabling PDF JavaScript in Reader where supported, a standard Adobe mitigation for this class of flaw. Verify installed versions against the vendor's affected-version list and monitor CISA and vendor advisories for updated indicators, noting ransomware use remains unconfirmed.

Affected
Adobe Acrobat
Adobe Reader
Estimated exposure
mass≈1M+ legacy/unpatched installs worldwide (Acrobat/Reader installed base is in the hundreds of millions) — Adobe Acrobat and Reader are among the most widely deployed desktop PDF clients with a cumulative installed base in the hundreds of millions, so even a small unpatched fraction plausibly leaves a million or more vulnerable systems; the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.

CISA Known Exploited Vulnerability
Affected
Adobe Acrobat and Reader
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Acrobat and Reader
Weakness
CWE-119

In the news