CVE-2007-5659

HIGH KEV

Adobe Acrobat and Reader < 8.1.2 - Remote Code Execution via Long JavaScript Method Arguments

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2007-5659 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 8, 2022. EIP tracks 3 public exploits from researchers including Metasploit, Paul Craig, MC, including a Metasploit module exploits/windows/fileformat/adobe_collectemailinfo.

AI-analyzed exploit summary This exploit leverages a buffer overflow in Adobe Reader and Acrobat Professional 8.1.1 via a malformed Collab.collectEmailInfo() call in a crafted PDF. It uses JavaScript obfuscation and heap spraying to achieve remote code execution.

Description

Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/16674

This exploit leverages a buffer overflow in Adobe Reader and Acrobat Professional 8.1.1 via a malformed Collab.collectEmailInfo() call in a crafted PDF. It uses JavaScript obfuscation and heap spraying to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Adobe Reader v8.1.1, Adobe Acrobat Professional v8.1.1
No auth needed
Prerequisites: Victim must open the malicious PDF file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Paul Craig · textdoswindows
https://www.exploit-db.com/exploits/31114

This exploit leverages a heap spray technique to trigger a buffer overflow in Adobe Acrobat/Reader via the `Collab.collectEmailInfo` method, allowing arbitrary code execution. The PoC uses a NOP sled (`%u9090`) and a placeholder shellcode (`%ucccc`).

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Adobe Acrobat and Reader < 8.1.2
No auth needed
Prerequisites: Victim must open a malicious PDF file · JavaScript must be enabled in Adobe Reader
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GOOD
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/adobe_collectemailinfo.rb

This Metasploit module exploits a buffer overflow in Adobe Reader/Acrobat 8.1.1 via a malformed Collab.collectEmailInfo() call in a crafted PDF. It generates a PDF with embedded JavaScript to trigger the vulnerability and execute arbitrary shellcode.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Adobe Reader and Adobe Acrobat Professional 8.1.1
No auth needed
Prerequisites: Victim must open the malicious PDF file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (14)

Core 14
Core References
Broken Link, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA08-043A.html
Broken Link vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1966/references
Broken Link third-party-advisory x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=657
Broken Link vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-239286-1
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200803-01.xml
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29065
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30840
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29205
Broken Link vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-0144.html
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/666281

Scores

CVSS v3 7.8
EPSS 0.9287
EPSS Percentile 99.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-06-08
VulnCheck KEV 2009-03-20
InTheWild.io 2012-12-01
ENISA EUVD EUVD-2007-5631
CWE
CWE-120
Status published
Products (2)
adobe/acrobat < 8.1.2
adobe/acrobat_reader < 8.1.2
Published Feb 12, 2008
KEV Added Jun 08, 2022
Tracked Since Feb 18, 2026