Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-2992

98
FAUCET Score

CVE-2008-2992 is a critical stack-based buffer overflow vulnerability affecting Adobe Acrobat and Reader versions 8.1.2 and earlier. This flaw allows remote attackers to execute arbitrary code by crafting a malicious PDF file that leverages the util.printf JavaScript function with a specially designed format string. With a CVSS score of 7.8 (High), exploitation requires user interaction (opening a malicious PDF) but can lead to complete compromise of confidentiality, integrity, and availability. The vulnerability is actively exploited, listed in CISA's KEV catalog with known ransomware campaign use, and has multiple public Metasploit modules and ExploitDB entries, indicating widespread exploit availability and significant community attention.

Impacted Technologies

VendorProductVersion(s)CPE
<= 8.1.2CPE matchmatch criteria
cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
<= 8.1.2CPE matchmatch criteria
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
10CPE matchmatch criteria
cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
98.48%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Added to KEV · Mar 3, 2022
Metasploit: Adobe util.printf() Buffer Overflow · Feb 8, 2008
ExploitDB: EDB-16624 · Sep 25, 2010
This CVE's current EPSS score of 0.9848 is in the 100th percentile among its peer group of 11,616 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

adobepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 3Fixed in: acroread-0:8.1.3-1
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: acroread-0:8.1.3-1.el4
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: acroread-0:8.1.3-1.el5
View patch

Vendor Advisories (1)

redhatCVE-2008-2992Critical

Reader: JavaScript util.printf() function buffer overflow

Nov 4, 2008

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
download.oracle.com / sunalerts/1019937.1.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2008-11/msg00002.html
Mailing ListThird Party Advisory
osvdb.org / 49520
Broken Link
secunia.com / advisories/29773
Broken LinkVendor Advisory
secunia.com / advisories/32700
Broken LinkVendor Advisory
secunia.com / advisories/32872
Broken LinkVendor Advisory
secunia.com / advisories/35163
Broken LinkVendor Advisory
secunia.com / secunia_research/2008-14
Broken LinkVendor Advisory
securityreason.com / securityalert/4549
Broken LinkExploit
support.nortel.com / go/main.jsp
Broken Link
support.nortel.com / go/main.jsp
Broken Link
exploit-db.com / exploits/6994
Third Party AdvisoryVDB Entry
exploit-db.com / exploits/7006
ExploitThird Party AdvisoryVDB Entry
adobe.com / support/security/bulletins/apsb08-19.html
Broken LinkPatchVendor Advisory
coresecurity.com / content/adobe-reader-buffer-overflow
Third Party Advisory
kb.cert.org / vuls/id/593409
Third Party AdvisoryUS Government Resource
redhat.com / support/errata/RHSA-2008-0974.html
Broken LinkPatch
securityfocus.com / archive/1/498027/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / archive/1/498032/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / archive/1/498055/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/30035
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/32091
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
us-cert.gov / cas/techalerts/TA08-309A.html
Broken LinkThird Party AdvisoryUS Government Resource
vupen.com / english/advisories/2008/3001
Broken LinkVendor Advisory
vupen.com / english/advisories/2009/0098
Broken LinkVendor Advisory
zerodayinitiative.com / advisories/ZDI-08-072
Third Party AdvisoryVDB Entry