Desktop Software
Memory Corruption
Adobe Reader Type Confusion - Memory Corruption Vulnerability
Adobe Reader Type Confusion – Memory Corruption Vulnerability This vulnerability allows remote attackers to execute code on vulnerable installations of Adobe Reader.
.png)
Overview
Adobe Reader Type Confusion – Memory Corruption Vulnerability
This vulnerability allows remote attackers to execute code on vulnerable installations of Adobe Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of TTF Font dictionary within a PDF file. The issue results from the lack of proper validation of user-supplied data. An attacker can leverage this vulnerabilities to execute code (RCE) in the context of the current process.
Vulnerability details
Adobe Reader Type Confusion – Memory Corruption Vulnerability This vulnerability allows remote attackers to execute code on vulnerable installations of Adobe Reader.
Disclosure timeline
2016-12-05 Reported to vendor
2017-04-06 Coordinated public release of advisory
References
Credits
Ashfaq Ansari – Project Srishti
















