CVE-2008-2992
HIGH severity · CVSS 7.8 · Out-of-bounds write · actively exploited (CISA KEV)
7.8CVSS HIGH exploited ransomware
Actively exploited in the wild (CISA Known Exploited Vulnerabilities).
Known use in ransomware campaigns. Added to KEV 2022-03-03. US federal agencies must patch by 2022-03-24.
Summary
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104.
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges requiredNone
User interactionRequired
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)98%
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products we track (2)
Recommendation
This vulnerability is being actively exploited in the wild — patch affected products urgently. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://secunia.com/advisories/29773Advisory
- http://secunia.com/advisories/32700Advisory
- http://secunia.com/advisories/32872Advisory
- http://secunia.com/advisories/35163Advisory
- http://secunia.com/secunia_research/2008-14/Advisory
- http://download.oracle.com/sunalerts/1019937.1.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlAdvisory
- http://osvdb.org/49520