Skip to main content

Adobe Products JavaScript Method Code Execution Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 25 Jun 2008 5250 Views

RISK: Medium Risk

A vulnerability has been identified in Adobe Reader and Acrobat, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by an unspecified input validation error in a JavaScript method, which could allow attackers to execute arbitrary code by tricking a user into opening a specially crafted PDF document.

Note: There are reports that this issue is being exploited in the wild.


Impact

  • Remote Code Execution

System / Technologies affected

  • Adobe Reader versions 8.0 through 8.1.2
  • Adobe Reader version 7.0.9 and prior
  • Adobe Acrobat Professional versions 8.0 through 8.1.2
  • Adobe Acrobat Professional version 7.0.9 and prior
  • Adobe Acrobat 3D versions 8.0 through 8.1.2
  • Adobe Acrobat 3D version 7.0.9 and prior
  • Adobe Acrobat Standard versions 8.0 through 8.1.2
  • Adobe Acrobat Standard version 7.0.9 and prior

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link