Junglewise Threat Intelligence

CVE-2017-2972: Adobe Acrobat Reader memory corruption in JPEG parsing

CVE-2017-2972 · Severity: high · CVSS 7.8 · Published 2017-01-24

Technologies: Adobe Acrobat, Adobe Reader, Adobe Acrobat Dc, Adobe Acrobat Reader Dc. Vendors: Adobe.

Executive brief

Adobe Acrobat and Reader are widely used applications for viewing and managing PDF documents. A vulnerability in how these programs process JPEG images could allow an attacker to take control of a user's computer if the user opens a specially crafted file. This could lead to the theft of sensitive data, unauthorized software installation, or disruption of business operations.

Technical details

A memory corruption vulnerability exists in the image conversion module of Adobe Acrobat and Reader. The flaw is specifically related to the parsing of JPEG image data, categorized as an improper restriction of operations within the bounds of a memory buffer (CWE-119). An attacker can exploit this by tricking a user into opening a malicious PDF file containing a crafted JPEG. Successful exploitation allows for arbitrary code execution in the context of the current user. The vulnerability affects both the Classic and Continuous tracks of Acrobat DC/Reader DC, as well as Acrobat/Reader XI. Adobe has released patches to address this issue in APSB17-01.

Affected products

  • Adobe Acrobat DC 15.020.20042 and earlier (Continuous), 15.006.30244 and earlier (Classic)
  • Adobe Acrobat Reader DC 15.020.20042 and earlier (Continuous), 15.006.30244 and earlier (Classic)
  • Adobe Acrobat 11.0.18 and earlier
  • Adobe Reader 11.0.18 and earlier

Timeline

  • 2017-01-24: disclosed
  • 2017-01-24: advisory
  • 2017-01-24: patched: Fixed in APSB17-01

References

Related threats