Lucene search

K
zdiSebastian ApeltsiberasZDI-16-320
HistoryMay 10, 2016 - 12:00 a.m.

Adobe Reader DC XFA Page Array Out-Of-Bounds Read Information Disclosure Vulnerability

2016-05-1000:00:00
Sebastian Apeltsiberas
www.zerodayinitiative.com
19

EPSS

0.059

Percentile

93.5%

This vulnerability allows remote attackers to gain information about the layout of memory on vulnerable installations of Adobe Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the Page array. A specially crafted PDF file can force Adobe Reader DC to read memory past the end of the Page object array. An attacker can use this information in conjunction with other vulnerabilities to execute code in the context of the process.