LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2009-0927: Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2009-0927 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.

CVE-2009-0927 is a stack-based buffer overflow in Adobe Reader and Adobe Acrobat that can let a remote attacker execute arbitrary code. It matters because these products are widely used to open PDF documents from email, web downloads, and shared drives; a successful exploit can give an attacker control of the host under the privileges of the user who opened the file.

Public detail is limited to the CISA summary and the stated weakness class. Confirm exact product builds, attack vectors, and fixes against the vendor advisory before acting.

How it works

The vulnerability is classified under CWE-20 (Improper Input Validation) and is described as a stack-based buffer overflow. In this class of flaw, the application fails to properly validate or bound the size of data it copies into a fixed-size buffer on the stack. When a crafted PDF or related input exceeds that buffer, adjacent stack memory can be overwritten.

An attacker abuses the condition by supplying a malicious file that the vulnerable Reader or Acrobat process parses. If the overflow is controllable, the attacker can overwrite return addresses or other control data and redirect execution to attacker-supplied code. The CISA summary states that this allows remote attackers to execute arbitrary code. No further exploit mechanics, specific file structures, or proof-of-concept details are provided in the given facts; treat any deeper technical claims as unconfirmed until verified against the vendor advisory.

Am I affected? How to find it in your systems

Adobe Reader and Adobe Acrobat commonly run on end-user workstations and some shared or terminal-server environments where users open PDFs. Inventory every host that has either product installed.

Because version ranges and configuration prerequisites are not supplied in the facts, treat any host running these products as potentially affected until the vendor advisory is consulted.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Obtain the security update that addresses CVE-2009-0927 directly from Adobe, validate its integrity, and deploy it through your normal change process to all affected Reader and Acrobat installations.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to a remote-code-execution buffer overflow in a document viewer.

These measures lower risk but do not eliminate it; schedule the official patch as soon as possible.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to host compromise and subsequent data theft. Known ransomware use is not documented for CVE-2009-0927, yet any successful code execution still warrants incident-response scrutiny. If you suspect exposure, preserve relevant logs, isolate affected systems, and follow your organization’s breach-investigation procedures. You can also run a free exposure scan of your email addresses to check whether they appear in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · Reader and Acrobat
WeaknessCWE-20
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities