Skip to content
COOEY

EXPOSURES › CVE-2008-0655

CVE-2008-0655

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-06-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2008-0655 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatchedrce

A design flaw in Adobe Acrobat and Reader allowed silent, arbitrary printing of specially crafted files, marking it as an actively exploited vulnerability.

This vulnerability exploited a design flaw enabling silent, arbitrary printing of crafted files, representing a significant compliance and operational risk for DIB organizations relying on Adobe products. The failure highlights Adobe's high-risk track record of critical RCE vulnerabilities, requiring constant vigilance and remediation efforts. Organizations should ensure all Adobe software is patched to the latest version and consider alternative solutions to mitigate ongoing exposure.

Shame score — The vulnerability was a design flaw that was actively exploited, reflecting Adobe's high-risk track record of repeated critical RCE vulnerabilities in its widely used products.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an arbitrary number of times.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized