CVE-2009-3459
HIGH KEVAdobe Acrobat < 9.1.3 - Remote Code Execution via Crafted PDF File
Title source: llmExploitation Summary
CVE-2009-3459 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 20, 2026.
EIP tracks 4 public exploits from researchers including Metasploit, unknown, jduck, jabra, unknown, jduck, including a Metasploit module exploits/windows/browser/adobe_flatedecode_predictor02.
AI-analyzed exploit summary This exploit leverages an integer overflow vulnerability in Adobe Reader and Acrobat Professional versions before 9.2 via a malformed FlateDecode stream with a Predictor value of 02. It uses JavaScript heap spraying to achieve remote code execution.
Description
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.
Exploits (4)
This exploit leverages an integer overflow vulnerability in Adobe Reader and Acrobat Professional versions before 9.2 via a malformed FlateDecode stream with a Predictor value of 02. It uses JavaScript heap spraying to achieve remote code execution.
This exploit leverages an integer overflow vulnerability in Adobe Reader and Acrobat Professional versions before 9.2 via a maliciously crafted PDF file with a FlateDecode stream. It uses JavaScript heap spraying to achieve remote code execution.
This Metasploit module exploits an integer overflow vulnerability in Adobe Reader and Acrobat Professional versions before 9.2 via a maliciously crafted PDF file. It uses JavaScript heap spraying and a FlateDecode stream with a manipulated Predictor value to achieve remote code execution.
This Metasploit module exploits an integer overflow vulnerability in Adobe Reader and Acrobat Professional versions before 9.2 via a maliciously crafted PDF file. It uses JavaScript heap spraying and a FlateDecode stream with a manipulated Predictor value to achieve remote code execution.
References (13)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H