KLA10004
Multiple Adobe Acrobat & Reader vulnerabilities
Обновлено: 17/06/2019
Дата обнаружения
13/05/2014
Уровень угрозы
Critical
Описание

Multiple serious vulnerabilities have been found in Adobe Reader & Adobe Acrobat versions X and XI. Malicious users can exploit these vulnerabilities to execute arbitrary code, bypass a sandbox protection, cause a denial of service or obtain sensitive information.

Below is a complete list of vulnerabilities

  1. Vectors related to unknown can be exploited to bypass a sandbox protection mechanism, execute arbitrary code or cause a denial of service via heap-based buffer overflow, use-after-free and double free.

  2. Vectors related to JavaScript API can be exploited to obtain sensitive information via a specially designed PDF

  3. Vectors related to unknown API calls can be exploited to execute arbitrary code via unmapped memory access.

Пораженные продукты

Adobe Reader & Acrobat XI 11.0.06 and earlier versions for Windows and Macintosh,
Adobe Reader & Acrobat X 10.1.9 and earlier versions for Windows and Macintosh.

Решение

Update to latest version
Reader

Первичный источник обнаружения
Adobe bulletin
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

SB 
[?]
Связанные продукты
Adobe Reader
Adobe Acrobat
Adobe Acrobat X
Adobe Acrobat XI
CVE-IDS
CVE-2014-051110.0Critical
CVE-2014-05214.3Warning
CVE-2014-052610.0Critical
CVE-2014-052510.0Critical
CVE-2014-052910.0Critical
CVE-2014-052710.0Critical
CVE-2014-052810.0Critical
CVE-2014-052210.0Critical
CVE-2014-051210.0Critical
CVE-2014-052410.0Critical
CVE-2014-052310.0Critical