Description
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104.
In plain language
AI Act nowCVE-2008-2992 is a serious Adobe Acrobat/Reader bug where a specially made PDF can trigger code execution on the user’s computer; small businesses should treat it as urgent if they use Adobe Acrobat or Adobe Reader (including older 8.1.2 and earlier).
CVE-2008-2992 is a stack-based buffer overflow in Adobe Acrobat and Adobe Reader triggered by a crafted PDF that abuses the PDF JavaScript call to `util.printf`, enabling remote code execution; it has been confirmed in the CISA KEV set and is known to be used in ransomware campaigns.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2008-2992 and every CVE in our database. Create a free account — no credit card required.
Create Free Account