CVE-2009-3956

CRITICAL

The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecified impact and att...

Affects 5 products across 4 vendors.

BCS7.8
CVSS 2.010.0
EPSS7.7%
Percentile94th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-16: CWE-16
◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2010. A critical vulnerability affects Adobe systems (CVE-2009-3956). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2010-GLOBAL-325034-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2009-3956?
This vulnerability was disclosed in 2010. A critical vulnerability affects Adobe systems (CVE-2009-3956). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2009-3956?
CVE-2009-3956 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 7.7%.
Is CVE-2009-3956 actively exploited?
No confirmed active exploitation of CVE-2009-3956 as of 2026-05-30.
How do I remediate CVE-2009-3956?
Priority: MEDIUM. Advisory: http://www.adobe.com/support/security/bulletins/apsb10-02.html PSIRT: [email protected]
What systems are affected by CVE-2009-3956?
CVE-2009-3956 affects: Adobe, Adobe, Apple, Microsoft, Unix.
Vulnerability Details
CVE IDCVE-2009-3956
BSIDBS-2010-GLOBAL-325034-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2010-01-13
Last Modified2026-04-23
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecified impact and attack vectors, related to a "script injection vulnerability," as demonstrated by Acrobat Forms Data Format (FDF) behavior that allows cross-site scripting (XSS) by user-assisted remote attackers.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecified impact and attack vectors, related to a "script injection vulnerability," as demonstrated by Acrobat Forms Data Format (FDF) behavior that allows cross-site scripting (XSS) by user-assisted remote attackers. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Adobe Acrobat Reader
Adobe Acrobat
Apple Mac Os X
Microsoft Windows
Unix Unix
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 6048 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash5243c5a21cd0f7f98655bcf3997c3856dceb8592b8120f706a500cfccac687d9b7aaad2323dc78857f9313dac88f4b38802963c2039910a2d43a4fa45e58e4a3
Related CVEs affecting Adobe
CVE-2013-3357 10.0 Integer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11... CVE-2015-5101 10.0 Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.15 ... CVE-2015-6691 10.0 Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.16 ... CVE-2004-1152 10.0 Buffer overflow in the mailListIsPdf function in Adobe Acrobat Reader 5.09 fo... CVE-2004-1153 10.0 Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allow...
View all Adobe CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →