CVE-2009-3953 KEV EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 83.2% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-22.
Description
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than CVE-2009-2994.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 83.22% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-787 |
| On CISA KEV | yes — remediate by 2022-06-22 |
| Public exploit | yes |
| Published | 2010-01-13 |
| Last modified | 2026-06-16 |
CISA KEV
| Name | Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability |
|---|---|
| Added | 2022-06-08 |
| Due | 2022-06-22 |
| Vendor / product | Adobe / Acrobat and Reader |
| Ransomware use | none reported |
Affected (6)
| Vendor | Product |
|---|---|
| adobe | acrobat |
| apple | mac os x |
| microsoft | windows |
| opensuse | opensuse |
| suse | linux enterprise |
| suse | linux enterprise debuginfo |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Adobe - U3D CLODProgressiveMeshDeclaration Array Overrun (Metasploit) (2) | 2010-09-25 |
References
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html
- http://osvdb.org/61690
- http://secunia.com/advisories/38138
- http://secunia.com/advisories/38215
- http://www.adobe.com/support/security/bulletins/apsb10-02.html
- http://www.metasploit.com/modules/exploit/windows/fileformat/adobe_u3d_meshdecl
- http://www.redhat.com/support/errata/RHSA-2010-0060.html
- http://www.securityfocus.com/bid/37758
- http://www.securitytracker.com/id?1023446
- http://www.us-cert.gov/cas/techalerts/TA10-013A.html
- http://www.vupen.com/english/advisories/2010/0103
- https://bugzilla.redhat.com/show_bug.cgi?id=554293
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55551
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8242
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html
- http://osvdb.org/61690
- http://secunia.com/advisories/38138
- http://secunia.com/advisories/38215
- http://www.adobe.com/support/security/bulletins/apsb10-02.html
- http://www.metasploit.com/modules/exploit/windows/fileformat/adobe_u3d_meshdecl
→ the Explorer · watch your stack · NVD