Skip to content
COOEY

EXPOSURES › CVE-2007-5659

CVE-2007-5659

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-06-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2007-5659 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatchedransomware

A buffer overflow in Adobe Acrobat and Reader allowed remote attackers to execute code via malicious PDF files.

This vulnerability enabled remote code execution through crafted PDF files, posing a severe risk to organizations relying on Adobe products for document handling. DIB entities must ensure all Adobe software is patched to the latest version to prevent exploitation, as this flaw was actively exploited in the wild and linked to ransomware campaigns.

Shame score — Adobe repeatedly shipped critical RCE vulnerabilities in its widely deployed Acrobat and Reader products, demonstrating a pattern of negligence that directly enables ransomware and data breaches.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized