Lucene search

K
zdiAbdulAziz Hariri - HP Zero Day InitiativeZDI-15-509
HistoryOct 13, 2015 - 12:00 a.m.

Adobe Acrobat Reader DC app.launchURL Command Execution Remote Code Execution Vulnerability

2015-10-1300:00:00
AbdulAziz Hariri - HP Zero Day Initiative
www.zerodayinitiative.com
22

EPSS

0.014

Percentile

86.6%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Acrobat Reader DC. Authentication is not required to exploit this vulnerability. The specific flaw exists within handling URL’s passed to app.launchURL. A specially crafted cURL passed to app.launchURL can force a command to be executed. A remote attacker could exploit this vulnerability to execute arbitrary code in the context of the process.

EPSS

0.014

Percentile

86.6%