Adobe Acrobat and Reader PDF Handling Code Execution Vulnerability
RISK: Medium Risk
A vulnerability has been identified in Adobe Acrobat and Reader, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a memory corruption error in the "authplay.dll" module when processing malformed Flash data within a PDF document, which could be exploited by attackers to execute arbitrary code by tricking a user into opening a PDF file embedding a malicious Flash animation.
Impact
- Remote Code Execution
System / Technologies affected
- Adobe Reader version 9.3 and prior
- Adobe Reader version 8.2 and prior
- Adobe Acrobat version 9.3 and prior
- Adobe Acrobat version 8.2 and prior
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to version 9.3.1 or 8.2.1 :
http://www.adobe.com/support/security/bulletins/apsb10-07.html
Vulnerability Identifier
Source
Related Link
Share with