PoC Index

CVE-2009-3953

KEVHIGH 10.0EPSS 83.9%

The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than CVE-2009-2994.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
83.86% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2022-06-08
Published
2010-01-13
Updated
2025-10-22

Proof-of-concept exploits (1)

Metasploit modules (1)

ExploitDB entries (1)

References

Related