CVE-2009-0658 is a critical buffer overflow vulnerability affecting Adobe Reader and Acrobat versions 9.0 and earlier. This flaw allows remote attackers to execute arbitrary code on a victim's system by tricking them into opening a specially crafted PDF document, potentially involving a non-JavaScript function call or an embedded JBIG2 image stream. With a CVSS score of 7.8 (High), the vulnerability requires user interaction (opening the PDF) but can lead to complete compromise of confidentiality, integrity, and availability. It was actively exploited in the wild in February 2009 by Trojan.Pidief.E, and multiple Metasploit modules and ExploitDB entries confirm the availability of exploit code, despite limited recent community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0, <= 7.1.1CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 8.0, <= 8.1.4CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:9.0:*:*:*:*:*:*:* | ||
>= 7.0, <= 7.1.1CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* | ||
>= 8.0, <= 8.1.4CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.