Adobe Patches 11 Critical Bugs in Popular Acrobat PDF Reader
#1
Information 
Quote:Eleven critical bugs in Adobe’s popular and free PDF reader, Acrobat, open both Window and macOS users to attacks ranging from an adversary arbitrarily executing commands on a targeted system to data leakage tied to system-read and memory flaws.
 
In a Tuesday security bulletin, which included patches for all flaws, the company reported that Windows and macOS versions of Acrobat were equally vulnerable. Adobe added however that it was not aware of any abuse of the bugs in the wild.
 
The free Acrobat Reader 2020 and PDF-creation and editing software Acrobat 2020 were among the list of those programs with critical bugs patched. Adobe also patched Acrobat DC, Acrobat DC Reader, Acrobat Reader 2017 and Acrobat 2017. In all, Adobe patched 20 Acrobat bugs, with nine rated important.

Two of the most serious Acrobat vulnerabilities are use-after-free flaws (CVE-2021-28641, CVE-2021-28639) that, in a worst case scenario, allow an adversary to execute code arbitrarily on targeted systems or just create application crashes.
 
One of the more interesting critical bugs patched is a type of vulnerability called an “uncontrolled search path element” flaw (CVE-2021-28636). The vulnerability class also goes by the names DLL preloading, insecure library loading and dependency confusion. It’s unclear how the weakness was introduced to Adobe Acrobat. The security bulletin links to a generic description of the flaw which states:
 
“The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors… In some cases, the attack can be conducted remotely, such as when SMB or WebDAV network shares are used,” according to a MITRE description of the vulnerability type.

Read more: Adobe Patches 11 Critical Bugs in Popular Acrobat PDF Reader | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AMD Strix Halo iGPU naming revealed: Rad...
Please note that t...harlan4096 — 12:36
Waterfox 6.5.1
6.5.1​ Fixes​ ...harlan4096 — 12:34
QOwnNotes 19.1.6
24.11.1 The mar...Kool — 15:27
Intel Core Ultra 200S Arrow Lake-S desk...
Intel confirms Core ...harlan4096 — 08:46
How (not) to play tanks and catch a back...
Cybercriminals hav...harlan4096 — 17:59

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (39)idilamoz
avatar (56)Stefanos
avatar (29)alison30
avatar (29)marcojanson42

[-]
Online Staff
There are no staff members currently online.

>