CVE-2009-3953
Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
YesDecision
Descriptions
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than CVE-2009-2994.
La implementación U3D en Adobe Reader y Acrobat v9.x anterior a v9.3, y v8.x anterior a v8.2 sobre Windows y Mac OS X, podría permitir a atacantes ejecutar código de su elección a través de vectores no especificados, relacionados con una "cuestión de limitación en el array".
Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-11-16 CVE Reserved
- 2010-01-13 CVE Published
- 2010-09-25 First Exploit
- 2022-06-08 Exploited in Wild
- 2022-06-22 KEV Due Date
- 2024-08-07 CVE Updated
- 2024-11-12 EPSS Updated
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (16)
URL | Tag | Source |
---|---|---|
http://osvdb.org/61690 | Broken Link | |
http://secunia.com/advisories/38138 | Broken Link | |
http://secunia.com/advisories/38215 | Broken Link | |
http://www.metasploit.com/modules/exploit/windows/fileformat/adobe_u3d_meshdecl | Third Party Advisory | |
http://www.securityfocus.com/bid/37758 | Broken Link | |
http://www.securitytracker.com/id?1023446 | Broken Link | |
http://www.us-cert.gov/cas/techalerts/TA10-013A.html | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/55551 | Third Party Advisory | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8242 | Broken Link |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/16622 | 2010-09-25 |
URL | Date | SRC |
---|---|---|
http://www.adobe.com/support/security/bulletins/apsb10-02.html | 2024-06-28 |
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html | 2024-06-28 | |
http://www.redhat.com/support/errata/RHSA-2010-0060.html | 2024-06-28 | |
http://www.vupen.com/english/advisories/2010/0103 | 2024-06-28 | |
https://bugzilla.redhat.com/show_bug.cgi?id=554293 | 2010-01-20 | |
https://access.redhat.com/security/cve/CVE-2009-3953 | 2010-01-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Acrobat Search vendor "Adobe" for product "Acrobat" | >= 7.0 < 7.1.4 Search vendor "Adobe" for product "Acrobat" and version " >= 7.0 < 7.1.4" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Acrobat Search vendor "Adobe" for product "Acrobat" | >= 7.0 < 7.1.4 Search vendor "Adobe" for product "Acrobat" and version " >= 7.0 < 7.1.4" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Acrobat Search vendor "Adobe" for product "Acrobat" | >= 8.0 < 8.2 Search vendor "Adobe" for product "Acrobat" and version " >= 8.0 < 8.2" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Acrobat Search vendor "Adobe" for product "Acrobat" | >= 8.0 < 8.2 Search vendor "Adobe" for product "Acrobat" and version " >= 8.0 < 8.2" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Acrobat Search vendor "Adobe" for product "Acrobat" | >= 9.0 < 9.3 Search vendor "Adobe" for product "Acrobat" and version " >= 9.0 < 9.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Acrobat Search vendor "Adobe" for product "Acrobat" | >= 9.0 < 9.3 Search vendor "Adobe" for product "Acrobat" and version " >= 9.0 < 9.3" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Suse Search vendor "Suse" | Linux Enterprise Debuginfo Search vendor "Suse" for product "Linux Enterprise Debuginfo" | 11 Search vendor "Suse" for product "Linux Enterprise Debuginfo" and version "11" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Opensuse Search vendor "Opensuse" for product "Opensuse" | 11.1 Search vendor "Opensuse" for product "Opensuse" and version "11.1" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Opensuse Search vendor "Opensuse" for product "Opensuse" | 11.2 Search vendor "Opensuse" for product "Opensuse" and version "11.2" | - |
Affected
| ||||||
Suse Search vendor "Suse" | Linux Enterprise Search vendor "Suse" for product "Linux Enterprise" | 10.0 Search vendor "Suse" for product "Linux Enterprise" and version "10.0" | sp2 |
Affected
| ||||||
Suse Search vendor "Suse" | Linux Enterprise Search vendor "Suse" for product "Linux Enterprise" | 10.0 Search vendor "Suse" for product "Linux Enterprise" and version "10.0" | sp3 |
Affected
|