Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2009-2990Adobe Acrobat vulnerability

CWE-18911 documents9 sources
Severity
9.3CRITICALNVD
EPSS
89.1%
top 0.46%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedOct 19
Latest updateMay 2

Description

Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitrary code via unspecified vectors.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDadobe/acrobat_reader9.1.3+25
NVDadobe/acrobat9.1.3+23

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rqh9-p568-89pc: Array index error in Adobe Reader and Acrobat 92022-05-02
VulnCheck
Adobe Reader and Acrobat Arbitrary Code Execution2009

💥Exploits & PoCs

3
Exploit-DB
Adobe - U3D CLODProgressiveMeshDeclaration Array Overrun (Metasploit) (1)2010-09-20
Exploit-DB
Adobe Reader / Acrobat - '.U3D' File Invalid Array Index Overflow2009-11-09
Metasploit
Adobe U3D CLODProgressiveMeshDeclaration Array Overrun

🔍Detection Rules

1
Suricata
ET WEB_CLIENT Adobe Reader and Acrobat U3D File Invalid Array Index Remote Code Execution Attempt2011-01-15

📋Vendor Advisories

1
Red Hat
acroread: Multiple arbitrary code execution fixes in 8.1.7 (APSB09-15)2009-10-13

🕵️Threat Intelligence

2
Talos
The Acrobat JavaScript Blocklist Framework2010-01-20
Talos
The Acrobat JavaScript Blocklist Framework2010-01-20

💬Community

1
Bugzilla
acroread: Multiple arbitrary code execution fixes in 8.1.7 (APSB09-15)2009-10-13
CVE-2009-2990 — Adobe Acrobat vulnerability | cvebase