Executive brief
Adobe Acrobat and Reader are widely used applications for viewing and managing PDF documents. A security flaw in these programs could allow an attacker to take control of a user's computer if the user opens a specially crafted file. This could lead to the theft of sensitive data, unauthorized software installation, or a complete system compromise.
Technical details
A heap-based buffer overflow vulnerability exists in the XSLT engine of Adobe Acrobat and Reader. The flaw is triggered during the manipulation of XSLT templates within a PDF document. An attacker can exploit this by convincing a user to open a maliciously crafted PDF file. Successful exploitation grants the attacker the ability to execute arbitrary code in the context of the current user. The vulnerability affects Continuous, Classic, and Desktop versions of Acrobat and Reader on both Windows and macOS. Adobe has released patches to address this issue in advisory APSB17-01.
Affected products
- Adobe Acrobat DC / Acrobat Reader DC (Continuous) 15.020.20042 and earlier
- Adobe Acrobat DC / Acrobat Reader DC (Classic) 15.006.30244 and earlier
- Adobe Acrobat / Reader 11.0.18 and earlier
Timeline
- 2017-01-24: disclosed
- 2017-01-24: advisory
- 2017-01-24: patched: Fixed in APSB17-01