CVE-2009-3459
high
📛 Threat Title
Adobe Acrobat and Reader: Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
Description
Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption. Added to KEV: 2026-05-20. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-06-03.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
cwe
CWE-119
IOC database
- Type
- cwe
- Value
CWE-119- First seen
- Last seen
- Attached to this threat
- Appears in
- 4 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2009-3459
IOC database
- Type
- cve
- Value
CVE-2009-3459- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (15)
- Vendor Advisory CISA KEV CVEs
- NVD reference CISA KEV CVEs
- Vendor Advisory CISA KEV CVEs
- NVD reference CISA KEV CVEs
- Patch, Vendor Advisory CISA KEV CVEs
- NVD reference CISA KEV CVEs
- NVD reference CISA KEV CVEs
- US Government Resource CISA KEV CVEs
- Vendor Advisory CISA KEV CVEs
- Vendor Advisory CISA KEV CVEs
- NVD reference CISA KEV CVEs
-
NVD detail: CVE-2009-3459
CISA KEV CVEs
Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
- NVD reference CISA KEV CVEs
- CISA notes reference CISA KEV CVEs
- CISA notes reference CISA KEV CVEs
Remediations (9)
-
web:dailycve.com
How the mentioned CVE works: The vulnerability resides in the PDF parsing logic of Adobe Reader and Acrobat, specifically within the handling of a malformed U3D (Universal 3D) object embedded in a PDF file. A heap-based buffer overflow occurs when the application processes a specially crafted PDF with an insufficiently validated length field. When the PDF is opened, the parser allocates a heap ...
-
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
-
web:tuxcare.com
It includes discovering vulnerabilities, evaluating their potential impact, prioritizing remediation efforts (including patching), and confirming the fixes. Patch Management Patch management, on the other hand, is the act of applying the necessary updates to fix known vulnerabilities. It's a critical component of vulnerability management.
-
web:www.bugcrowd.com
Vulnerability mitigation is typically considered a temporary or interim solution. While mitigation measures can reduce the immediate risk associated with vulnerabilities, they may not provide a permanent fix . Organizations should aim to prioritize and plan for complete vulnerability remediation whenever feasible and allocate resources accordingly.
-
web:www.scyscan.com
Description Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
-
web:www.cisa.gov
If vulnerabilities cannot be remediated within the recommended timeframes, develop a remediation plan for action and coordination across the organization. The remediation plan should include: Vulnerability remediation constraints Interim mitigation actions to overcome constraints Final actions required to remediate vulnerability
-
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
-
web:www.microsoft.com
These Knowledge Base articles accompany all security updates and advisories, and include caveats or known issues with security updates. Additionally, support engineers document common concerns from customers in these KB articles. These Knowledge Base articles are published the Security Update Guide with each release on Patch Tuesday.
-
CISA KEV (via KEVin)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-06-03
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.