Adobe Patches 11 Critical Bugs in Popular Acrobat PDF Reader
#1
Information 
Quote:Eleven critical bugs in Adobe’s popular and free PDF reader, Acrobat, open both Window and macOS users to attacks ranging from an adversary arbitrarily executing commands on a targeted system to data leakage tied to system-read and memory flaws.
 
In a Tuesday security bulletin, which included patches for all flaws, the company reported that Windows and macOS versions of Acrobat were equally vulnerable. Adobe added however that it was not aware of any abuse of the bugs in the wild.
 
The free Acrobat Reader 2020 and PDF-creation and editing software Acrobat 2020 were among the list of those programs with critical bugs patched. Adobe also patched Acrobat DC, Acrobat DC Reader, Acrobat Reader 2017 and Acrobat 2017. In all, Adobe patched 20 Acrobat bugs, with nine rated important.

Two of the most serious Acrobat vulnerabilities are use-after-free flaws (CVE-2021-28641, CVE-2021-28639) that, in a worst case scenario, allow an adversary to execute code arbitrarily on targeted systems or just create application crashes.
 
One of the more interesting critical bugs patched is a type of vulnerability called an “uncontrolled search path element” flaw (CVE-2021-28636). The vulnerability class also goes by the names DLL preloading, insecure library loading and dependency confusion. It’s unclear how the weakness was introduced to Adobe Acrobat. The security bulletin links to a generic description of the flaw which states:
 
“The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors… In some cases, the attack can be conducted remotely, such as when SMB or WebDAV network shares are used,” according to a MITRE description of the vulnerability type.

Read more: Adobe Patches 11 Critical Bugs in Popular Acrobat PDF Reader | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Microsoft Edge 145.0.3800.58
Version 145.0.3800...harlan4096 — 09:28
AnyDesk 9.6.11 for Windows / 9.6.3 for m...
AnyDesk 9.6.11 for...harlan4096 — 09:03
Google Chrome 145.0.7632.75/76
Google Chrome 145....harlan4096 — 08:59
Vivaldi 7.8 Build 3925.66
Vivaldi 7.8 Build ...harlan4096 — 08:58
New Windows 11 Update Adds Built-In Sysm...
Microsoft is rolli...harlan4096 — 10:11

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (38)showercurtains
avatar (49)PeterWhink
avatar (46)dimaWeami
avatar (39)TranoTymn
avatar (39)MezirLal
avatar (38)Michaelaburi
avatar (46)dpascoal
avatar (51)Ronaldduh
avatar (39)legalgauch
avatar (44)Baihu
avatar (27)RaseinsLikes

[-]
Online Staff
There are no staff members currently online.

>