Junglewise Threat Intelligence

CVE-2017-2929: Adobe Acrobat Chrome extension DOM-based XSS

CVE-2017-2929 · Severity: medium · CVSS 6.1 · Published 2017-01-24

Technologies: Adobe Acrobat, Microsoft Windows. Vendors: Adobe, Microsoft.

Executive brief

The Adobe Acrobat extension for the Google Chrome web browser contains a security flaw that could allow an attacker to run malicious code in a user's browser. This extension is commonly used to view and manage PDF documents directly within the web browser. If exploited, an attacker could potentially steal sensitive information or perform actions on behalf of the user on websites they are currently visiting.

Technical details

A DOM-based cross-site scripting (XSS) vulnerability exists in the Adobe Acrobat Chrome extension (versions 15.1.0.3 and earlier). The flaw is categorized as CWE-79 and stems from improper neutralization of input during web page generation within the Document Object Model (DOM) environment. An unauthenticated remote attacker can exploit this by enticing a user to visit a specially crafted webpage or click a malicious link. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized data access. Adobe has released a patch to address this issue in advisory APSB17-03.

Affected products

  • Adobe Acrobat Chrome extension 15.1.0.3 and earlier

Timeline

  • 2017-01-24: disclosed
  • 2017-01-24: advisory: Adobe released security bulletin APSB17-03
  • 2017-01-24: patched

References

Related threats