EXPOSURES › CVE-2009-3953
CVE-2009-3953
HIGH ⌖ ON CISA KEV · EXPLOITEDA vulnerability in Adobe Acrobat and Reader allowed attackers to execute code remotely via malicious 3D files, actively exploited in the wild and impacting DIB organizations reliant on these tools for document handling.
CVE-2009-3953, an array boundary issue in Adobe Acrobat and Reader's Universal 3D support, enabled remote code execution. DIB organizations using these products are at risk of malware infection and data compromise, potentially impacting CMMC compliance. Immediate patching and user awareness training are crucial.
Shame score — The vulnerability's age and active exploitation despite Adobe's prominent position highlights a pattern of negligent security practices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |