LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2007-5659: Adobe Acrobat and Reader Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 8, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 22, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2007-5659 to its Known Exploited Vulnerabilities catalog on Jun 8, 2022, with a federal patch deadline of Jun 22, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods.

CVE-2007-5659 is a buffer overflow vulnerability in Adobe Acrobat and Reader. A crafted PDF that passes overly long arguments to certain JavaScript methods can let a remote attacker execute code on the system that opens the file. Because PDF viewers are common on endpoints and the attack arrives as a document users may open, the issue matters for any organization that handles untrusted or external PDFs.

Public detail is limited to the class of flaw and the high-level abuse path described by CISA. Confirm exact affected builds, fixed versions, and deployment guidance against the vendor advisory before acting.

How it works

The weakness is CWE-119: improper restriction of operations within the bounds of a memory buffer. In this case, Adobe Acrobat and Reader fail to adequately bound the length of arguments supplied to unspecified JavaScript methods inside a PDF. An attacker who can deliver a malicious PDF can supply oversized input that overflows a buffer.

If the overflow is controllable, it can corrupt memory in a way that allows arbitrary code execution in the context of the user who opens the document. No further exploit mechanics are provided in the available facts; treat any claimed payload details as unconfirmed unless they appear in the vendor advisory or a trusted analysis that cites it. The practical attack path is social or email delivery of a PDF that the victim opens in a vulnerable Acrobat or Reader instance with JavaScript processing enabled.

Am I affected? How to find it in your systems

Adobe Acrobat and Reader typically run on user workstations and virtual desktops where staff open PDFs from email, file shares, or the web. Servers that convert or render PDFs with these products can also be in scope.

If you cannot map builds to the advisory, treat systems still running unsupported or unpatched Acrobat/Reader as potentially affected until proven otherwise.

How to remediate

Patch first. Apply the updates Adobe published for this issue, following the vendor instructions referenced in the CISA required action. Confirm installation of the fixed builds across the estate and verify that automatic update channels (where used) have actually delivered the correct packages.

If you can't patch immediately

Reduce risk with compensating controls until the vendor update is deployed everywhere.

These steps do not replace the patch; they only buy time.

If your data may have been exposed

Actively exploited document vulnerabilities can lead to endpoint compromise and follow-on data theft. The available facts do not document ransomware use for this CVE, but any successful code execution still warrants incident response: isolate affected hosts, preserve memory and disk evidence, rotate credentials that may have been accessible from the compromised session, and check for persistence or lateral movement. You can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior dumps while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · Acrobat and Reader
WeaknessCWE-119
Added to CISA KEVJun 8, 2022
Federal patch deadlineJun 22, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities