CVE-2009-3953
Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than CVE-2009-2994.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 83.86% probability · 100th percentile
- CISA KEV
- Listed 8 June 2022 · due 22 June 2022
- Weakness
- CWE-787
- Affected
- adobe/acrobat · suse/linux enterprise debuginfo · opensuse/opensuse · suse/linux enterprise
- Source
- psirt@adobe.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2009-3953
References
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.htmlMailing List, Third Party Advisory
- http://osvdb.org/61690Broken Link
- http://secunia.com/advisories/38138Broken Link
- http://secunia.com/advisories/38215Broken Link
- http://www.adobe.com/support/security/bulletins/apsb10-02.htmlNot Applicable, Patch, Vendor Advisory
- http://www.metasploit.com/modules/exploit/windows/fileformat/adobe_u3d_meshdeclThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0060.htmlBroken Link
- http://www.securityfocus.com/bid/37758Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1023446Broken Link, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA10-013A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2010/0103Broken Link, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=554293Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55551Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8242Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.htmlMailing List, Third Party Advisory
- http://osvdb.org/61690Broken Link
- http://secunia.com/advisories/38138Broken Link
- http://secunia.com/advisories/38215Broken Link
- http://www.adobe.com/support/security/bulletins/apsb10-02.htmlNot Applicable, Patch, Vendor Advisory
- http://www.metasploit.com/modules/exploit/windows/fileformat/adobe_u3d_meshdeclThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0060.htmlBroken Link
- http://www.securityfocus.com/bid/37758Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1023446Broken Link, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA10-013A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2010/0103Broken Link, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=554293Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55551Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8242Broken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-3953US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.