Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability.

Release Date: 15th May 2026

Impact : HIGH / CRITICAL

TLP Rating: Clear

The Department of Communication and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2009-3459 is a critical remote code execution (RCE) vulnerability affecting Adobe Reader and Adobe Acrobat.

The vulnerability is caused by a buffer overflow and memory corruption flaw in the handling of specially crafted PDF files containing embedded JavaScript and malformed objects.

 

References

  1. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  2. https://www.cve.org/CVERecord?id=CVE-2009-3459