Lucene search

K
saintSAINT CorporationSAINT:5A2653F986460BD7AF17F567584EFD70
HistoryMar 30, 2011 - 12:00 a.m.

Adobe Reader Flash AVM2 Memory Corruption

2011-03-3000:00:00
SAINT Corporation
download.saintcorporation.com
24

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.971

Percentile

99.8%

Added: 03/30/2011
CVE: CVE-2011-0609
BID: 46860
OSVDB: 71254

Background

Adobe Reader is free software for viewing PDF documents.

Problem

Adobe Reader 9.x is vulnerable to a remote code execution vulnerability as a result of parsing flash content by the bundled Adobe Flash Player.

Resolution

Update Adobe Flash Player to version 10.2.153.1 or later, Adobe AIR to version 2.6 or later, Adobe Reader X to version 10.0.2 or later, and Adobe Reader to version 9.4.3 or later.

References

<http://www.kb.cert.org/vuls/id/192052&gt;
<http://www.adobe.com/support/security/advisories/apsa11-01.html&gt;
<http://googlechromereleases.blogspot.com/2011/03/stable-and-beta-channel-updates_15.html&gt;

Limitations

This exploit works against Adobe Systems Adobe Reader 9.4.0 running on Microsoft Windows XP SP3 English (DEP AlwaysOff) or Microsoft Windows Vista SP2 English (DEP AlwaysOff).

Platforms

Windows

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.971

Percentile

99.8%