Skip to main content

Adobe Acrobat and Reader PDF Handling Code Execution Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 18 Feb 2010 4359 Views

RISK: Medium Risk

A vulnerability has been identified in Adobe Acrobat and Reader, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a memory corruption error in the "authplay.dll" module when processing malformed Flash data within a PDF document, which could be exploited by attackers to execute arbitrary code by tricking a user into opening a PDF file embedding a malicious Flash animation.


Impact

  • Remote Code Execution

System / Technologies affected

  • Adobe Reader version 9.3 and prior
  • Adobe Reader version 8.2 and prior
  • Adobe Acrobat version 9.3 and prior
  • Adobe Acrobat version 8.2 and prior

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link