Lucene search

K
zdiPeter VreugdenhilZDI-08-072
HistoryNov 04, 2008 - 12:00 a.m.

Adobe Acrobat PDF Javascript printf Stack Overflow Vulnerability

2008-11-0400:00:00
Peter Vreugdenhil
www.zerodayinitiative.com
42

EPSS

0.973

Percentile

99.9%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Acrobat. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists in the handling of embedded Javascript code when opening a PDF. Adobe Acrobat has defined it’s own set of Javascript functions that can be used in a PDF file. Due to improper parameter checking to one of these functions arbitrary memory can be over-written leading to remote code execution. If successfully exploited remote control of the target system can be gained with the credentials of the logged in user.