Skip to content
COOEY

EXPOSURES › CVE-2009-0927

CVE-2009-0927

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2009-0927 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 rceexploited-in-wildunpatched

Adobe Reader and Acrobat contained a stack-based buffer overflow allowing remote attackers to execute arbitrary code.

This stack-based buffer overflow in Adobe Reader and Acrobat allowed remote attackers to execute arbitrary code, representing a critical RCE vulnerability. DIB organizations must ensure these products are patched immediately, as Adobe has a high-risk track record of repeated critical RCE vulnerabilities in its Acrobat and Reader products. Failure to patch exposes systems to remote code execution, which can lead to data breaches, ransomware, and compliance violations.

Shame score — Adobe repeatedly ships critical RCE vulnerabilities in widely deployed products, demonstrating a pattern of negligence and a high-risk track record that shreds trust.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized