CVE ID | CVE-2008-2992 |
CVSS SCORE | |
AFFECTED VENDORS |
Adobe |
AFFECTED PRODUCTS |
Acrobat |
VULNERABILITY DETAILS |
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Acrobat. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists in the handling of embedded Javascript code when opening a PDF. Adobe Acrobat has defined it's own set of Javascript functions that can be used in a PDF file. Due to improper parameter checking to one of these functions arbitrary memory can be over-written leading to remote code execution. If successfully exploited remote control of the target system can be gained with the credentials of the logged in user. |
ADDITIONAL DETAILS |
Adobe has issued an update to correct this vulnerability. More details can be found at:
http://www.adobe.com/support/security/bulletins/apsb08-19.html |
DISCLOSURE TIMELINE |
|
CREDIT | Peter Vreugdenhil |