Desktop Software

Memory Corruption

Adobe Reader Type Confusion - Memory Corruption Vulnerability

Adobe Reader Type Confusion – Memory Corruption Vulnerability This vulnerability allows remote attackers to execute code on vulnerable installations of Adobe Reader.

7.8
/ 10
High
CVSS v3.0
ADVISORY ID
PS4
PUBLISHED
2022-10-02
CVE IDs
CVE-2017-3038
VENDORS
Adobe
PUBLIC EXPLOIT
None indexed
CWE
CWE-119
PRODUCT
Adobe Acrobat/Reader DC
CVSS VECTOR
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Adobe Reader Type Confusion – Memory Corruption Vulnerability

This vulnerability allows remote attackers to execute code on vulnerable installations of Adobe Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the parsing of TTF Font dictionary within a PDF file. The issue results from the lack of proper validation of user-supplied data. An attacker can leverage this vulnerabilities to execute code (RCE) in the context of the current process.

Vulnerability details

Vulnerability details

CVE-2017-3038
CWE-119
High | 7.8

Adobe Reader Type Confusion – Memory Corruption Vulnerability This vulnerability allows remote attackers to execute code on vulnerable installations of Adobe Reader.

Auth:
None (local access, user interaction required)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
DISCLOSURE

Disclosure timeline

2016-12-05 Reported to vendor

2017-04-06 Coordinated public release of advisory

Credits

Ashfaq Ansari – Project Srishti