ZeroHour
Cisco Talospublished ()ingested Nick Biasini

Vulnerability Spotlight: Adobe Acrobat Reader DC jpeg Decoder Vulnerability

highVulnerability exploited in the wildimportance 60CVE-2017-2971

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-2971
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability in the JPE

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability in the JPEG decoder routine. Successful exploitation could lead to arbitrary code execution.

NVD description · AI analysis pending
7.89%
  • adobe acrobat
  • adobe acrobat dc
  • adobe acrobat reader dc
  • +1 more
Full article162 words · extracted from blog.talosintelligence.com · click to collapse

Friday, January 20, 2017 11:56

Discovered by Aleksandar Nikolic of Cisco Talos

Overview

Talos is disclosing TALOS-2016-0259 / CVE-2017-2971 an uninitialized memory vulnerability in Adobe Acrobat Reader DC. Adobe Acrobat Reader is one of the largest and well known PDF readers available today.

This particular vulnerability is associated with the JPEG Decoder functionality embedded in the application. A specially crafted PDF document containing a JPEG can be used to trigger this vulnerability which results in a heap-based buffer overflow which can be leveraged to achieve remote code execution. This issue has been resolved in the most recent patch provided by Adobe. The full details surrounding the vulnerability are available here.

Coverage

The following Snort Rules will detect exploitation attempts. Note that additional rules may be released at a future date and current rules are subject to change pending additional vulnerability information. For the most current rule information, please refer to your FireSIGHT Management Center or Snort.org.

Snort Rule: 41298 - 41305

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/adobe-acrobat-jpeg-vuln/