vendor:
Acrobat Reader DC
by:
Anonymous
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Acrobat Reader DC
Affected Version From: Adobe Acrobat Reader DC
Affected Version To: Latest version
Patch Exists: YES
Related CWE: N/A
CPE: a:adobe:acrobat_reader_dc
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2020
Access Violation Exception in Adobe Acrobat Reader DC for Windows
When opening a malformed PDF file, an access violation exception is triggered in the latest version of Adobe Acrobat Reader DC for Windows. This is due to a buffer overflow vulnerability in the CoolType!CTInit+0x3913e function, which is caused by an invalid memory access when writing to the address 0x707703a4. This can be exploited to execute arbitrary code in the context of the application.
Mitigation:
Adobe has released an update to address this vulnerability.