Adobe Reader U3D auto-activated 3D annotation — CVE-2009-2990

CVE_2009_2990_U3D_AUTOACTIVATE

← All detection heuristics · PDF

critical CVE_2009_2990_U3D_AUTOACTIVATE

What it means

PDF embeds a U3D stream behind a /3D annotation set to auto-activate on page view.

Why it fires

CVE-2009-2990 is a heap buffer overflow in Adobe Reader / Acrobat's U3D (Universal 3D, ECMA-363) CLODProgressiveMeshDeclaration parser, patched in APSB09-15 (Reader 9.2 / 8.1.7 / 7.1.4) alongside the sibling FlateDecode-predictor overflow CVE-2009-3459. The exploitable document shape is a /Subtype /3D annotation whose /3DA activation dictionary binds /A /PV with /AIS /I — that combination makes the U3D parser run on page view with no click required. Real-world samples pair this with a 0x0c0c0c0c heap-spray JavaScript that lays a urlmon-based download shellcode at the corrupted allocation. Legitimate 3D PDFs almost never use the auto-activate + JS combination.

Other PDF heuristics

PDF_LAUNCH_JS_PROTOCOL PDF_LAUNCH_COMMAND PDF_LAUNCH_MSHTA PDF_ADOBE_QR_UNLOCK_LURE PDF_JS_URL_KEYED_READER_EXPLOIT_KIT PDF_ANNOT_AUTHOR_EVAL_STAGER PDF_ANNOT_SUBJECT_HEX_EVAL_STAGER PDF_ANNOT_SUBJECT_MARKER_EVAL_STAGER PDF_JS_BASE_N_TOKEN_DOWNLOADER PDF_BASE64_PE_PAYLOAD PDF_BRAND_INVOICE_LURE_OFFDOMAIN PDF_BRAND_INVOICE_CLOUD_EMAIL_LURE PDF_CORPORATE_PRESENTATION_CLOUD_REDIRECT_LURE PDF_CORRUPTED_FILE_UPDATE_LURE PDF_CRACKED_SOFTWARE_SHORTLINK_LURE PDF_GAME_HACK_SEO_LINK_FARM PDF_DISTRIBUTED_PIRACY_LINK_FARM PDF_DOCUSIGN_DOWNLOAD_LURE PDF_DOCUMENT_ACTION_HOST_MISMATCH_LURE PDF_DYNAMIC_DNS_DOCUMENT_LINK_FARM PDF_SWF_NATIVE_MEMORY_CORRUPTION_PAYLOAD PDF_EMBEDDED_PE_PAYLOAD CVE_2010_1240_EMBEDDED_EXPORT_LAUNCH CVE_2021_30860