Knox CVE Database
/
CVE-2009-3459
Critical
9.3

CVE-2009-3459: Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.

Added to the CISA KEV catalog:
May 20, 2026

Overview

Adobe Reader and Acrobat contain a heap-based buffer overflow in the PDF parsing engine that allows an attacker to corrupt process memory and execute arbitrary code. Versions 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 on Windows, Macintosh, and UNIX are affected. Adobe confirmed active exploitation in limited, targeted attacks in October 2009, making this a high-priority patching target for any environment still running older Reader or Acrobat builds.

Vulnerability details

Affected vendor
Adobe
Affected product
Acrobat and Reader
Weakness type (CWE)
CWE-119, CWE-122

When Adobe Reader or Acrobat parses a PDF file, it allocates a heap buffer to hold parsed content. A malformed PDF can supply data that exceeds the bounds of that allocation, overwriting adjacent heap memory. This class of flaw (CWE-122) allows an attacker to corrupt heap metadata or function pointers in a controlled way, redirecting execution to attacker-supplied code. The application performs insufficient size validation on the parsed input, so the overflow occurs before any bounds check can intervene.


An attacker delivers a crafted PDF to the target, via email attachment or a malicious web page hosting the file, and waits for the victim to open it in a vulnerable Reader or Acrobat installation. No authentication or elevated privilege is required on the attacker's side. Once the victim opens the file, the overflow executes arbitrary code with the privileges of the user running the application. Adobe's own advisory noted reports of this issue being exploited in the wild through limited, targeted attacks at the time of disclosure.

Severity and impact

9.3
Critical
AV:N/AC:M/Au:N/C:C/I:C/A:C
Attack vector
Network
Attack complexity
Medium
Privileges required
User interaction
Scope
Confidentiality impact
Complete
Integrity impact
Complete
Availability impact
Complete

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor endpoint process telemetry for Adobe Reader or Acrobat spawning unexpected child processes (cmd.exe, powershell.exe, wscript.exe, or network-connected processes) immediately after a PDF is opened, which is not part of normal Reader operation and indicates post-exploitation activity.
  • Alert on Reader or Acrobat processes making outbound network connections to destinations not matching Adobe update infrastructure, particularly connections initiated within seconds of a PDF file being rendered, as the application has no legitimate reason to initiate arbitrary outbound sessions during document parsing.

Remediation

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal (FCEB) remediation due date
June 3, 2026

Additional hardening

  • Upgrade Adobe Acrobat and Reader to version 9.2 or later (for the 9.x line), 8.1.7 or later (for the 8.x line), or 7.1.4 or later (for the 7.x line) as specified in Adobe security bulletin APSB09-15.
  • Disable the Adobe Reader and Acrobat browser plug-ins in all browsers to eliminate drive-by delivery via malicious web pages; users should open PDFs only in the standalone application after upgrading.
  • Apply application allowlisting or exploit mitigation controls (such as DEP and ASLR enforcement) to Reader and Acrobat processes to reduce the reliability of heap overflow exploitation even on unpatched systems.
  • Restrict delivery of PDF attachments from untrusted external senders at the mail gateway, and configure sandboxed preview where available, to reduce the attack surface for targeted file-delivery campaigns.

Key dates

Published (NVD)
October 13, 2009
Added to CISA KEV
May 20, 2026
Remediation deadline
June 3, 2026
Last updated
June 16, 2026

References

Frequently asked questions

Does CVE-2009-3459 affect my FedRAMP authorization?

If Adobe Acrobat and Reader runs inside your authorization boundary, yes. CVE-2009-3459 appears in CISA's Known Exploited Vulnerabilities catalog, and its remediation deadline of June 3, 2026 is already behind you. For a FedRAMP-authorized service, an unpatched KEV in the boundary is a finding. An overdue one is a finding your assessor and sponsoring agency can see right now. Your options are to remediate immediately or formally document the mitigation and the delay.

How does Knox help me handle CVE-2009-3459?

Knox does not patch your software. Remediating Adobe Acrobat and Reader is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage to help you document the fix for your next assessment. Applying the patch is yours to own; managing your compliance posture while you do it is not something you have to handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. For a CVE like CVE-2009-3459, that means exposure surfaces during continuous monitoring rather than only when an assessor flags it at review time, giving you a shorter window between disclosure and response.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2009-3459's remediation deadline of June 3, 2026 has passed. What happens now?

If CVE-2009-3459 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding out and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship on solid ground.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.