Adobe Products JavaScript Method Code Execution Vulnerability
RISK: Medium Risk
A vulnerability has been identified in Adobe Reader and Acrobat, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by an unspecified input validation error in a JavaScript method, which could allow attackers to execute arbitrary code by tricking a user into opening a specially crafted PDF document.
Note: There are reports that this issue is being exploited in the wild.
Impact
- Remote Code Execution
System / Technologies affected
- Adobe Reader versions 8.0 through 8.1.2
- Adobe Reader version 7.0.9 and prior
- Adobe Acrobat Professional versions 8.0 through 8.1.2
- Adobe Acrobat Professional version 7.0.9 and prior
- Adobe Acrobat 3D versions 8.0 through 8.1.2
- Adobe Acrobat 3D version 7.0.9 and prior
- Adobe Acrobat Standard versions 8.0 through 8.1.2
- Adobe Acrobat Standard version 7.0.9 and prior
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to Adobe Reader version 8.1.2 Security Update 1 for Windows :
http://www.adobe.com/support/downloads/detail.jsp?ftpID=3967 - Upgrade to Adobe Reader version 8.1.2 Security Update 1 for Macintosh :
http://www.adobe.com/support/downloads/detail.jsp?ftpID=3966 - Upgrade to Adobe Acrobat version 8.1.2 Security Update 1 for Windows :
http://www.adobe.com/support/downloads/detail.jsp?ftpID=3976 - Upgrade to Adobe Acrobat version 8.1.2 Security Update 1 for Macintosh :
http://www.adobe.com/support/downloads/detail.jsp?ftpID=3977 - Upgrade to Adobe Acrobat 3D version 8.1.2 Security Update 1 for Windows :
http://www.adobe.com/support/downloads/detail.jsp?ftpID=3975 - Upgrade to Adobe Reader version 7.1.0 :
http://www.adobe.com/go/getreader - Upgrade to Adobe Acrobat version 7.1.0 for Windows :
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows - Upgrade to Adobe Acrobat version 7.1.0 for Macintosh :
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Macintosh
Vulnerability Identifier
Source
Related Link
Share with