PoC Index

CVE-2009-3459

KEVHIGH 9.3EPSS 86.6%

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
86.58% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2026-05-20
Published
2009-10-13
Updated
2026-05-21

Metasploit modules (1)

ExploitDB entries (2)

References

Related