June 8, 2022 · Applied Cybernetics Group
CVE-2009-3953 — Adobe Acrobat and Reader
Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability
- Added to KEV
2022-06-08- Federal due date
2022-06-22- Vendor
- Adobe
- Product
- Acrobat and Reader
- EPSS
- 99.6th percentile (score 0.905, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2009-3953
CISA short description
Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution.
Required action
Apply updates per vendor instructions.