CVE-2008-2992 is a stack-based buffer overflow in Adobe Acrobat and Adobe Reader 8.1.2 and earlier. The flaw is triggered when a malicious PDF invokes the JavaScript util.printf function with a crafted format string argument, causing memory corruption on the stack. Successful exploitation can allow remote code execution in the context of the user opening the PDF. The vulnerability was widely incorporated into exploit kits and used in drive-by exploitation chains targeting Adobe Reader.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a small proof-of-concept lab for CVE-2008-2992 centered on malicious PDF delivery against vulnerable Adobe Reader on a Windows 7 victim. It contains two code files and two documentation files. The main attacker workflow is in scripts/automated_hack.sh, a Bash automation script for Linux/Kali that installs gnome-terminal, derives the local IP address, uses Metasploit's exploit/windows/fileformat/adobe_pdf_embedded_exe module to generate a malicious PDF named myresume.pdf with a windows/meterpreter/reverse_tcp payload, launches a multi/handler listener on TCP port 4444, waits for the handler to initialize, and then uploads the PDF to the victim via anonymous FTP at 10.80.76.3. The exploit capability is therefore automated weaponization and delivery of a malicious PDF plus listener setup for a reverse shell. The victim-side helper is scripts/automated_user_behavior.py, a Windows Python script that continuously monitors C:\Users\vboxuser\Documents for new PDF files, opens them with the default application, and simulates keyboard input using ctypes/user32 keybd_event to navigate and confirm dialog boxes. Its purpose is to emulate user behavior and ensure the malicious PDF is opened and prompts are accepted, increasing exploit reliability in the lab. The documentation explains that the project targets CVE-2008-2992 and provides a prepared Windows 7 VM image with vulnerable Adobe Reader, Python, FTP server, and website components. Overall, this is a real exploit repository rather than a detector: it automates payload generation, delivery, and session handling, while relying on a controlled lab configuration and Metasploit modules for the actual exploitation mechanics.
This repository contains a single Metasploit module exploit targeting a buffer overflow vulnerability in Adobe Reader and Adobe Acrobat Professional versions prior to 8.1.3 (CVE-2008-2992). The exploit works by generating a specially crafted PDF file (default name: msf.pdf) containing obfuscated JavaScript that triggers a buffer overflow via the util.printf() function. When a victim opens the malicious PDF with a vulnerable version of Adobe Reader/Acrobat on Windows, the embedded shellcode is executed, allowing arbitrary code execution with the user's privileges. The module is fully integrated into the Metasploit framework, allowing for customizable payloads. The attack vector is local, requiring the victim to open the malicious file. The only fingerprintable endpoint is the generated PDF file itself. The code is mature and weaponized, suitable for real-world exploitation within the Metasploit ecosystem.
This repository contains a single Metasploit module (adobe_utilprintf.rb) that exploits a buffer overflow vulnerability in Adobe Reader and Adobe Acrobat Professional versions prior to 8.1.3 (CVE-2008-2992). The exploit works by serving a specially crafted PDF file containing malicious JavaScript that triggers a buffer overflow via the util.printf() function, allowing arbitrary code execution. The module is written in Ruby and leverages Metasploit's HttpServer::HTML mixin to deliver the PDF to victims who visit the attacker's web server. The payload is customizable and can be any Metasploit-compatible shellcode, typically resulting in a reverse shell or Meterpreter session on the victim's Windows machine. The exploit targets users who open the malicious PDF in a vulnerable version of Adobe Reader/Acrobat on Windows. The repository structure is typical for a Metasploit exploit module, with all logic contained in a single Ruby file.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Adobe vulnerability that CISA KEV’s knownRansomwareCampaignUse field silently flipped to Known during 2025 (evidence of ransomware campaign use).
A vulnerability in the Adobe Acrobat util.printf function used by exploit code to help infect victims with Bredolab.
An older vulnerability that persisted in multiple exploit kits over time.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.