EXPOSURES › CVE-2007-5659
CVE-2007-5659
HIGH ⌖ ON CISA KEV · EXPLOITEDA buffer overflow in Adobe Acrobat and Reader allowed remote attackers to execute code via malicious PDF files.
This vulnerability enabled remote code execution through crafted PDF files, posing a severe risk to organizations relying on Adobe products for document handling. DIB entities must ensure all Adobe software is patched to the latest version to prevent exploitation, as this flaw was actively exploited in the wild and linked to ransomware campaigns.
Shame score — Adobe repeatedly shipped critical RCE vulnerabilities in its widely deployed Acrobat and Reader products, demonstrating a pattern of negligence that directly enables ransomware and data breaches.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |