New 0-day Vulnerability in Adobe Acrobat Reader
Technical Description |
A vulnerability has been identified in Adobe Acrobat and Reader, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by a heap corruption error in the "EScript.api" plugin when processing the "printSeps()" function within a PDF document, which could be exploited by attackers to crash an affected application or compromise a vulnerable system by tricking a user into opening a specially crafted PDF file.
November 8, 2010 Update:
We plan to resolve this issue in the update for Adobe Reader and Acrobat 9.4 and earlier 9.x versions scheduled for release during the week of November 15, 2010, mentioned in Security Advisory APSA10-05. We have assigned CVE-2010-4091 to this issue. As of today, Adobe is not aware of any exploits in the wild or public exploit code for this issue.
Comments