peter bassill · operator
$ cve CVE-2009-3953 JSON

CVE-2009-3953 KEV EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 83.2% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-22.

Description

The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than CVE-2009-2994.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS83.22% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-787
On CISA KEVyes — remediate by 2022-06-22
Public exploityes
Published2010-01-13
Last modified2026-06-16

CISA KEV

NameAdobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability
Added2022-06-08
Due2022-06-22
Vendor / productAdobe / Acrobat and Reader
Ransomware usenone reported

Affected (6)

VendorProduct
adobeacrobat
applemac os x
microsoftwindows
opensuseopensuse
suselinux enterprise
suselinux enterprise debuginfo

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD