LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2008-2992: Adobe Reader and Acrobat Input Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2008-2992 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.

CVE-2008-2992 is an input validation vulnerability in Adobe Acrobat and Reader that affects a JavaScript method and can allow remote code execution. Attackers who can deliver a crafted PDF or related content may run code in the context of the user opening the file. CISA notes known ransomware use of this issue, so unpatched installations remain a practical risk for endpoint compromise and follow-on activity. Confirm exact product coverage and fixed builds against the vendor advisory.

How it works

The weakness is classified as CWE-119 (improper restriction of operations within the bounds of a memory buffer). In this class of flaw, software fails to correctly validate or bound input before using it in memory operations. Here, Adobe Acrobat and Reader contain an input validation issue in a JavaScript method. An attacker abuses that path by supplying malformed or unexpected input that the method does not handle safely, which can corrupt memory and potentially lead to remote code execution when the document is processed.

Technical readers should treat this as a classic client-side document parser / script-engine memory safety problem: the trigger is user- or content-driven input reaching the vulnerable method, not a network service listening by default. Exact exploit mechanics, payload formats, and preconditions are not detailed in the provided facts; rely on the vendor advisory for definitive technical description rather than assuming specific call stacks or heap layouts.

Am I affected? How to find it in your systems

Adobe Acrobat and Reader are commonly installed on Windows and other desktop endpoints used for viewing or editing PDFs—workstations, VDI images, kiosks, and any system where users open email attachments or downloaded documents. Inventory every host for Acrobat and Reader packages, including full, standard, and reader-only editions, and note whether JavaScript in PDFs is enabled (a common default that expands the attack surface for this class of issue).

If version or configuration detail is unclear, assume potential exposure until you verify against the advisory.

How to remediate

Patch first. Apply the updates Adobe published for this vulnerability, following the vendor instructions referenced in CISA’s required action. Deploy through your normal test-and-rollout process to endpoints, VDI templates, and any managed software distribution channels so that both interactive users and automated document workflows receive the fix.

If you can't patch immediately

Reduce exposure until the vendor update can be applied everywhere.

These steps are compensating controls only; they do not replace the vendor update.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, are frequently used to gain an initial foothold that leads to data theft or encryption. If you have evidence of exploitation or have run vulnerable Acrobat/Reader builds in environments that handle sensitive files, follow your incident response process: isolate affected hosts, preserve logs and memory where appropriate, credential-reset as needed, and assess whether ransomware or exfiltration occurred. You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public breach corpora and then prioritize password changes and MFA accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · Acrobat and Reader
WeaknessCWE-119
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities