vendor:
Reader
by:
Didier Stevens
4,3
CVSS
MEDIUM
Launch Action
N/A
CWE
Product Name: Reader
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2010
Escape From PDF
This is a special PDF hack which allows an embedded executable to be executed without exploiting any vulnerability. It uses a launch action triggered by the opening of the PDF. With Adobe Reader, the user gets a warning asking for approval to launch the action, but the message displayed by the dialog can be partially controlled. Foxit Reader displays no warning at all, the action gets executed without user interaction.
Mitigation:
Disable JavaScript and patching Adobe Reader.