cbcvebase.
CVE-2009-3953
published 2010-01-13

CVE-2009-3953: The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to…

PriorityP187high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-06-22
Exploited in the wild
EPSS
83.86%
99.7th percentile
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than CVE-2009-2994.

Affected

7 ranges
VendorProductVersion rangeFixed in
adobeacrobat>= 7.0 < 7.1.47.1.4
adobeacrobat>= 8.0 < 8.28.2
adobeacrobat>= 9.0 < 9.39.3
opensuseopensuse
opensuseopensuse
suselinux_enterprise
suselinux_enterprise_debuginfo

Detection & IOCsextracted from sources · hover to see the quote

filenamemsf.pdf
ip0x09011020
other0x7c49fb34
  • Malicious PDF containing malformed U3D (Universal 3D) stream data targeting CLODProgressiveMeshDeclaration array overflow; inspect PDF streams for embedded U3D objects with anomalous CLODProgressiveMeshDeclaration block sizes.
  • Exploit uses JavaScript heap spray (PREPAREHOLES + PREPAREMEMORY) embedded in the PDF; detect suspicious JavaScript inside PDF with heap-spray patterns (large repeated NOP sleds followed by shellcode) targeting Adobe Reader processes.
  • The exploit sets EXITFUNC to 'process', meaning the spawned process will terminate after shellcode execution; monitor for Adobe Reader child processes that exit abnormally or spawn unexpected child processes.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.